Aevral: A Modern GitHub Security Solution
Aevral is a GitHub security application created as a streamlined alternative to Claude Security. It combines two core products—whole‑repository scans and pull request reviews—into a single installation. Each product can operate independently, meaning organizations can choose to use one or both without dependency. Built by ISMS Copilot, Aevral emphasizes transparency, developer‑friendly integration, and organization‑based pricing.
Whole‑Repository Scans
Aevral’s repo scanning feature performs deep, at‑rest analysis of an entire codebase. It focuses on identifying complex flaws such as authorization issues, insecure direct object references (IDOR), and business‑logic vulnerabilities. Every finding is presented with evidence drawn directly from the repository, ensuring developers can trace issues back to their source. Importantly, Aevral provides honest coverage verdicts: if a scan is incomplete, the report explicitly states so. This transparency helps teams understand the true scope of their security posture. To aid remediation, Aevral offers fix prompts compatible with AI coding assistants like Claude Code, Cursor, or Codex, accelerating the patching process.
Pull Request Reviews
In addition to repo scans, Aevral acts as an automated reviewer on pull requests. This feature is opt‑in per organization and integrates seamlessly into GitHub workflows. Each PR receives a Check plus inline comments on added lines, focusing on authorization and business‑logic flaws. By embedding security checks directly into the development process, Aevral ensures that vulnerabilities are caught before code is merged. The system is designed so that nothing merges without explicit approval, reinforcing secure coding practices across teams.
Key Features
Repo scanning: Deep analysis of the entire codebase for logic and authorization flaws.
Pull request reviews: Automated inline comments on PRs to prevent insecure merges.
Fix assistance: AI‑powered prompts for rapid vulnerability remediation.
Transparent reporting: Honest verdicts on scan completeness.
Flexible hosting: Data processing available in the US or EU.
Flat pricing: Charges per organization, never per seat.
Pricing Structure
Aevral offers straightforward plans for both repo scanning and PR reviews. Public repositories are scanned free of charge, with one authorized scan per month. Private repositories benefit from tiered plans: Team (€99/month for 4 scans, then €29 per extra), Business (€399/month for 16 scans, then €19 per extra), Scale (€1,699/month for 100 scans, then €17 per extra), and Enterprise by quote. PR review plans are priced in USD: Free (25 private reviews per month), Starter ($19/month for 100 reviews, then $0.49 per extra), Pro ($99/month for 500 reviews, then $0.49 per extra), and Business ($249/month for 2,000 reviews, then $0.49 per extra).
Advantages
Aevral stands out for its cost‑effectiveness, offering free scans and reviews without requiring a card. Its scalability makes it suitable for small teams and large enterprises alike. By integrating with AI assistants, it reduces the time needed to fix vulnerabilities. Transparent reporting builds trust, while flexible hosting supports compliance with regional data requirements.
Conclusion
Aevral delivers a balanced approach to GitHub security, combining deep repo scans with proactive PR reviews. Its transparent reporting, AI‑driven fix assistance, and organization‑based pricing make it a compelling choice for teams seeking a modern, scalable alternative to Claude Security.
Explore more artificial intelligence tools on IndieHunt.

