Skip to content
winfunc
Application security

Application security, grounded in your code.

Investigate real attack paths, prove what is exploitable, and hand engineering a reviewed fix. One workflow from codebase audit to verified remediation.

What's included
  1. acme
  2. /billing-api
  3. /Vulnerabilities
  4. /WF-1042
Critical
Sourceroutes/invoices.ts:18
req.params.invoiceId
Sourceroutes/pdf.ts:31
req.query.invoice
1
Passed to the service without the caller's tenantinvoices.get(id)services/invoices.ts:42
2
Repository looks the invoice up by id alonerepo.findInvoice(id)repo/invoices.ts:71
Sinkrepo/invoices.ts:77
db.query("SELECT * FROM invoices WHERE id = $1", [id])

Cross-tenant invoice read through an unscoped lookup

CriticalCVSS 9.1
Weakness
CWE-639 · Authorization bypass
Confidence
97
Validation
Exploitable
Proof
Tenant A read tenant B's invoice in the sandbox
Finding · source to sinkIllustrative data
  1. Every place attacker-controlled input enters.
  2. Each hop is recorded with the code that carried the value.
  3. The dangerous operation, with no check on the path.
  4. Reproduced in an isolated sandbox before it reached you.
The problem

Scanners find patterns. Attackers find paths.

Rule-based tools flag what looks dangerous and leave your team to prove whether it is. winfunc starts from the application: its roles, its trust boundaries, its business rules. It follows the paths an attacker would take and reports only what the evidence supports.

Included

What winfunc covers.

  • Codebase audits pinned to an agreed scope and revision
  • Source-to-sink tracing through the paths that matter
  • Authorization, data-handling, and business-rule investigation
  • Findings linked to affected code with supporting evidence
  • Reproduction steps or proof-of-concept where testing is in scope
  • Dependency review across major package ecosystems
  • Suggested patches opened as pull requests
  • Pull-request and scheduled review as the code changes
Outcomes

What your team walks away with.

01

Application context

Roles, permissions, and business rules shape every investigation, and the assumptions behind each conclusion are written down.

02

Evidence you can inspect

Each finding shows affected locations, prerequisites, and proof, with observed behavior and inference kept separate.

03

Reviewable remediation

Patches follow your code's conventions and arrive as pull requests for your engineers to test and merge.

04

One connected workflow

Investigation, triage, remediation, and re-review share the same context from first finding to closed issue.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.