Skip to content
winfunc
winfunc Scanner

Detection, proof, and the fix, in one workspace.

SAST, SCA, IaC, secrets, and container scanning with validated findings, patches as pull requests, and analytics, all connected to the same application context.

Pricing
  1. acme
  2. /billing-api
  3. /Vulnerabilities
  4. /WF-1042
Critical
Sourceroutes/invoices.ts:18
req.params.invoiceId
Sourceroutes/pdf.ts:31
req.query.invoice
1
Passed to the service without the caller's tenantinvoices.get(id)services/invoices.ts:42
2
Repository looks the invoice up by id alonerepo.findInvoice(id)repo/invoices.ts:71
Sinkrepo/invoices.ts:77
db.query("SELECT * FROM invoices WHERE id = $1", [id])

Cross-tenant invoice read through an unscoped lookup

CriticalCVSS 9.1
Weakness
CWE-639 · Authorization bypass
Confidence
97
Validation
Exploitable
Proof
Tenant A read tenant B's invoice in the sandbox
Finding · source to sinkIllustrative data
  1. Every place attacker-controlled input enters.
  2. Each hop is recorded with the code that carried the value.
  3. The dangerous operation, with no check on the path.
  4. Reproduced in an isolated sandbox before it reached you.
Enterprise-ready

Ready for your security review.

SSO, zero data retention, customer-controlled deployment, and a complete audit trail.

Identity and access

  • SAML 2.0 single sign-on

    Sign in through Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 identity provider.

  • Federated login and provisioning

    Manage who gets access from the identity provider you already run.

  • Repository-scoped roles

    Owners decide who sees findings and who can run scans on each repository.

  • Revocable access keys

    API and MCP keys are stored only as SHA-256 hashes and can be revoked at any time.

Data protection

  • Zero data retention

    Source code is analyzed in ephemeral workspaces and deleted after each scan. Only findings are kept.

  • No training on your code

    Customer code and data are never used to train AI models.

  • Sealed credentials

    TLS on every connection. Test credentials are encrypted with per-record XChaCha20-Poly1305 keys.

  • Secret-free logs

    Logs keep request metadata only: never bodies, tokens, cookies, or authorization headers.

Deployment and models

  • Customer-controlled hostingEnterprise

    Run winfunc inside your own cloud or private environment.

  • Isolated tenantsEnterprise

    Dedicated single-tenant environments for regulated workloads.

  • Bring your own model keysEnterprise

    Route analysis through your own AI provider accounts and agreements.

  • Open-weight model support

    Proven in public research: the NGINX work behind five CVE IDs ran on open GLM models.

Oversight

  • Complete audit trail

    Every API request and authorization decision is logged for administrative review.

  • Least-privilege access

    winfunc reads only the repositories you select and never merges to protected branches.

  • Policy controls

    Repository rules set what each scan focuses on and reports, with organization-wide policies on Enterprise.

  • Named supportEnterprise

    A named security contact with contracted response terms.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.