FREEYour first GitHub repository audit is free. No card, every finding included.

HOW IT WORKS

From repository
to reviewed fix.

Connect GitHub, read the evidence, and decide what ships. Every step below is one you can see, and the important ones wait for you.

ONE AUDIT, START TO FINISHEXAMPLE
Step 1 of 7

Connect GitHub. Install the read-only Aster Code Audit App.

Illustration of one audit and fix with an example repository. Select a step to jump to it.

THE JOURNEY

Nine steps.
The big calls stay yours.

Steps one to five are your free audit. Fixes come with paid plans, and nothing reaches your repository until you confirm it.

AUDIT · FREERead-only, from the first click
  1. 01

    Connect GitHub

    Install the Aster Code Audit App. It asks for Contents: read and Metadata: read. Nothing more.

  2. 02

    Choose repositories

    Only the repositories you share with the App appear. Revoke access in GitHub whenever you like.

  3. 03

    Read a bounded snapshot

    Aster pins one commit and reads up to 80 text files and 2 MiB into memory. Nothing is cloned, installed or executed.

    What is read, exactly
  4. 04

    Run source checks

    Static checks for risky patterns, credential patterns, client and server boundaries, and syntax. You can leave the page while it works.

  5. 05

    Review findings by severity

    Each finding points to a file and a line, with the evidence and a next step in plain language. Every finding is included on the free audit.

    Anatomy of a finding
FIX · PAID PLANSYou confirm before anything is published
  1. 06

    Choose a model, see the cost

    Pick a supported model for each fix. The maximum credit cost is shown before anything runs, and the code goes only to the provider you chose.

    Supported models
  2. 07

    Review the diff, then confirm

    Aster proposes a focused change. You read the full diff and its validation status, then decide.

  3. 08

    A draft pull request, on a new branch

    Publishing uses the separately authorized Aster Fixes App. It opens a draft. Nothing is merged automatically.

VERIFYEvidence, not assumptions
  1. 09

    Merge, then audit again

    You review and merge on GitHub. A new audit of the merged code is what confirms the change, not the merge itself.

Step demos are illustrations with an example repository. Your results will differ.

ANATOMY OF A FINDING

Five parts.
No guesswork.

HIGHNeeds your review

User input reaches a raw SQL query

app/api/search.ts · line 9

8  const term = req.query.q9  return db.$queryRawUnsafe("… '" + term + "'")
WHAT ASTER NOTICED

A value from the request is added straight into a SQL string.

SUGGESTED NEXT STEP

Use a parameterized query so the value can’t change the query.

Example finding from a demo repository.
  • High, Medium or Low tells you where to start. It is a review priority; Aster does not reproduce runtime exploits.

CLEAR BOUNDARIES

What Aster does.
And what it never does.

Aster does

  • Read only the repositories you choose
  • Read a pinned snapshot, in memory
  • Show the file, line and evidence for each finding
  • Show the maximum credit cost before a fix runs
  • Open a draft pull request after you confirm

Aster does not

  • Write to your repository during an audit
  • Clone, install or execute your code
  • Send code to an AI model during a source audit
  • Merge anything automatically
  • Call a clean scan a security clearance

Permissions, retention and limits in full: Trust & scope

QUESTIONS

A little more
clarity.

Can I connect my repository today?

Yes. Connect GitHub, choose the repositories shared with the Aster App, and run your first read-only source audit. Paid memberships add AI-assisted fixes.

Do I have to keep the page open while it runs?

No. You can leave the dashboard while an audit runs and come back to its progress or the saved report.

Why not just ask my coding assistant?

You can, and you should use the review tools you already have. Aster adds a repeatable workflow: source checks, clear evidence, proposed changes and a visible validation status.

Will Aster change my code automatically?

No. The audit connection is read-only. To publish a fix, you separately authorize Aster Fixes on selected repositories and confirm the change. It creates a new branch and a draft pull request; nothing is merged automatically.

Does a clean scan mean my app is secure?

No. Any automated review has limits. Reports explain scope and skipped files, and critical systems may still need specialist review.

How much does it cost?

Your first repository audit is free. Pro is $49 a month, or $294 billed yearly. Team is $99 a month, or $594 billed yearly. Compare plans

See your first
findings, free.

Connect GitHub, choose a repository, and read what comes back. Your first audit is free.

Aster

Hi, I’m Aster.

I can help with your first audit, plans, or connecting GitHub. What can I help you with?

Prepared site guidance