Aevral is an AI security reviewer for GitHub pull requests. Built by Better ISMS, the company behind ISMS Copilot, in Paris, France.
Install the GitHub App and the next pull request gets a security review: an advisory GitHub Check plus inline comments on the added lines, at most five findings per review. The review looks for access control, business logic, SQL and command injection, XSS, SSRF, path traversal, unsafe deserialization, token and session flaws, and LLM-integration risks. Each finding is a lead with evidence and a suggested fix you apply in Claude Code, Cursor or Codex. Nothing merges without you.
A separate whole-repo scan reads the default branch for authorization, IDOR and business-logic access control.
Not a general SAST, and not secret, dependency or memory-corruption scanning. GitHub only. Open-source models, processed in the US today, with an EU-only option announced. Priced per organization, never per seat.
Pricing (USD per organization per month, excluding VAT). PR security review: public repositories free (500 reviews per organization per month); 25 private reviews a month free; signing in with GitHub starts a 14-day trial of up to 500 private reviews, no card. Starter $49, Pro $199, Business $999, Scale $1,999. Whole-repo scans: public repositories free (1 scan a month), Team $99, Business $399, Scale $1,699, Enterprise by quote. Details: aevral.com/pricing

