Detection, proof, and the fix, in one workspace.
SAST, SCA, IaC, secrets, and container scanning with validated findings, patches as pull requests, and analytics, all connected to the same application context.
- acme
- /billing-api
- /Vulnerabilities
- /WF-1042
invoices.get(id)services/invoices.ts:42repo.findInvoice(id)repo/invoices.ts:71Cross-tenant invoice read through an unscoped lookup
- Weakness
- CWE-639 · Authorization bypass
- Confidence
- 97
- Validation
- Exploitable
- Proof
- Tenant A read tenant B's invoice in the sandbox
- Every place attacker-controlled input enters.
- Each hop is recorded with the code that carried the value.
- The dangerous operation, with no check on the path.
- Reproduced in an isolated sandbox before it reached you.
Code, dependencies, infrastructure, secrets, and images.
SAST, SCA, IaC, secrets, and container scanning land in one workspace, with one evidence model and one fix workflow.
Static analysis (SAST)
Source-to-sink analysis with reproduction evidence and CVSS rationale for every finding.
ExploreSoftware composition analysis (SCA)
Reachability-aware SCA with SBOM export and license compliance across every major ecosystem.
ExploreInfrastructure as code (IaC)
Terraform, CloudFormation, Kubernetes, Helm, Docker, and CI pipelines reviewed in application context.
ExploreSecrets detection
Hardcoded credentials in code, config, and git history, with live validity checks.
ExploreContainer security
Image and layer scanning with Dockerfile attribution and base-image upgrade advice.
ExploreDecide faster, then ship the fix.
AI security assistant
Conversational triage grounded in your repository, findings, and scan history.
ExploreAutofix
Security patches delivered as pull requests, with job tracking and cost transparency.
ExplorePR security scanning
Diff-scoped review with findings on changed lines, suggested fixes, and explicit re-review.
ExploreKeep every change covered, and show the progress.
Ready for your security review.
SSO, zero data retention, customer-controlled deployment, and a complete audit trail.
Identity and access
SAML 2.0 single sign-on
Sign in through Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 identity provider.
Federated login and provisioning
Manage who gets access from the identity provider you already run.
Repository-scoped roles
Owners decide who sees findings and who can run scans on each repository.
Revocable access keys
API and MCP keys are stored only as SHA-256 hashes and can be revoked at any time.
Data protection
Zero data retention
Source code is analyzed in ephemeral workspaces and deleted after each scan. Only findings are kept.
No training on your code
Customer code and data are never used to train AI models.
Sealed credentials
TLS on every connection. Test credentials are encrypted with per-record XChaCha20-Poly1305 keys.
Secret-free logs
Logs keep request metadata only: never bodies, tokens, cookies, or authorization headers.
Deployment and models
Customer-controlled hostingEnterprise
Run winfunc inside your own cloud or private environment.
Isolated tenantsEnterprise
Dedicated single-tenant environments for regulated workloads.
Bring your own model keysEnterprise
Route analysis through your own AI provider accounts and agreements.
Open-weight model support
Proven in public research: the NGINX work behind five CVE IDs ran on open GLM models.
Oversight
Complete audit trail
Every API request and authorization decision is logged for administrative review.
Least-privilege access
winfunc reads only the repositories you select and never merges to protected branches.
Policy controls
Repository rules set what each scan focuses on and reports, with organization-wide policies on Enterprise.
Named supportEnterprise
A named security contact with contracted response terms.
Bring us your hardest codebase.
We'll bring the proof.
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
