Aevrin
Security review for MCP servers, with honest coverage and actionable fixes.
Review source repositories, live MCP servers, or pasted configuration through the same authenticated product workspace your team will use to triage, verify, and repeat scans. No invented trend lines. No fake confidence.
Coverage is explicit
Complete, partial, failed, skipped, and stale states are called out instead of hidden.
Findings stay operational
Evidence, remediation, OWASP MCP mapping, and repeat-scan verification live in one flow.
Built for real rollout
Use the dashboard, CLI, and Claude Code hook together without drifting into separate products.
Authenticated workflow preview
Review the available evidence before a server gets installed.
New scan
Start from the target you actually have
Source repository, live MCP server, or pasted config input. Aevrin explains the trade-off in coverage before you launch the scan.
- Source repo: broadest code, dependency, and secret coverage
- Live MCP server: runtime install decision, reduced static visibility
- Pasted config: fastest route for triage and follow-up
Result state
Partial scans stay partial
Coverage notes, skipped stages, and failed scanners remain visible on the result page so remediation decisions stay grounded.
Finding detail
Fixes are not just labels
A finding page explains where the issue lives, why it matters, how to fix it, and how to verify the fix with a repeat scan.
Rollout path
One product across browser, terminal, and hook
Install the CLI, log in with device flow, and use the Claude Code hook only where automated pre-install checks fit your process.
API keys stay reserved for CI and other non-interactive environments.
The product is designed around decision quality, not empty dashboard filler.
Real scanner evidence
Aevrin normalizes findings from the actual open-source tools in the scan pipeline. The CLI, API, and dashboard read the same vocabulary.
Honest completeness
Partial and failed stages are surfaced directly so a clean findings list never hides missing coverage, broken tooling, or network limits.
Actionable remediation
Each finding is framed around what happened, why it matters, how to fix it, and how to verify the fix with a repeat scan.
Developer workflow coverage
Use the dashboard for guided scans, the CLI for local review, and the Claude Code hook for pre-install decisions.
The product is organized around the questions security reviews actually produce.
What needs my attention right now?
What was scanned, how completely, and when?
Why is this finding dangerous?
How do I fix it?
How do I verify the fix actually worked?
Start with a dashboard scan
Review target type, coverage, stage failures, and remediation without installing anything locally first.
Move to CLI for repeated checks
Run the same scanner vocabulary from your own terminal when you want fast local confirmation before merge or install.
Add the hook for gatekeeping
Use the Claude Code pre-install check when you want unsafe MCP adds to warn or block before they touch a workstation.
Simple per-scan-type limits
No surprise overages, ever.
| Feature | Free | Hobby | Team |
|---|---|---|---|
| CLI scans | 5 / month | 50 / month | Unlimited |
| Hook auto-scans | 2 / month | 20 / month | Unlimited |
| Dashboard scans | 5 / month | 50 / month | Unlimited |
| Scan history retained | 7 days | 90 days | Unlimited |
| Accounts | 1 | 1 | 1 account |
| OWASP MCP-mapped report export | — |
Frequently asked questions
Prices are charged in US dollars through Razorpay. Taxes may apply. Aevrin pauses new scans at the configured limit and does not create automatic overage charges.
Set up Aevrin from a real terminal, not a marketing checklist.
Use the exact commands the current product supports. Device login is the default path for developers. API keys are for CI and other non-interactive automation.