Reviewable reports
Selected findings become a report with scope, methodology, evidence, remediation status, and known limits.
Organize scope, findings, remediation status, and limitations into reports for SOC 2, ISO 27001, customer questionnaires, and auditors.
Security assessment · billing-api
Jul 1 – Sep 30, 2026 · 4 repositories · 118 findings reviewed
| Framework | Control | Status |
|---|---|---|
| SOC 2 | CC7.1Vulnerability detection | Evidence |
| ISO 27001 | A.8.8Technical vulnerabilities | Evidence |
| PCI DSS | 6.3.3Known vulnerabilities patched | Evidence |
| SOC 2 | CC8.1Change management | 2 exceptions |
| HIPAA | 164.308(a)(8)Evaluation | Evidence |
Code review is a control on paper until someone can show what was reviewed, what was found, and what was fixed. winfunc keeps that trail automatically, and its reports stay traceable to the findings underneath.
Selected findings become a report with scope, methodology, evidence, remediation status, and known limits.
Repeated reviews record when findings were identified, assessed, and fixed.
Use findings and reports to answer customer security questionnaires with specifics instead of assurances.
winfunc is SOC 2 Type II audited, supports SSO and zero data retention, and signs DPAs and BAAs.
winfunc's evidence supports your assessment. Certification decisions remain with your auditor.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.