Skip to content
winfunc
Industry · Compliance & audit

Turn security work into audit-ready evidence.

Organize scope, findings, remediation status, and limitations into reports for SOC 2, ISO 27001, customer questionnaires, and auditors.

What's included
  1. acme
  2. /Reports
  3. /Q3 2026 assessment
Export PDF
86

Security assessment · billing-api

Jul 1 – Sep 30, 2026 · 4 repositories · 118 findings reviewed

FrameworkControlStatus
SOC 2CC7.1Vulnerability detectionEvidence
ISO 27001A.8.8Technical vulnerabilitiesEvidence
PCI DSS6.3.3Known vulnerabilities patchedEvidence
SOC 2CC8.1Change management2 exceptions
HIPAA164.308(a)(8)EvaluationEvidence
Report · control evidenceIllustrative data
The problem

Auditors want evidence, not screenshots.

Code review is a control on paper until someone can show what was reviewed, what was found, and what was fixed. winfunc keeps that trail automatically, and its reports stay traceable to the findings underneath.

Included

What winfunc covers.

  • Reports stating scope, method, findings, and limitations
  • Evidence linked to affected code and remediation status
  • Printable reports and exports
  • Review history as an evidence trail
  • Security scores and trends per repository
  • Summaries traceable to underlying findings
  • winfunc's own SOC 2 Type II documentation in the Trust Center
Outcomes

What your team walks away with.

01

Reviewable reports

Selected findings become a report with scope, methodology, evidence, remediation status, and known limits.

02

Evidence over time

Repeated reviews record when findings were identified, assessed, and fixed.

03

Questionnaires, answered

Use findings and reports to answer customer security questionnaires with specifics instead of assurances.

04

A vendor that passes review

winfunc is SOC 2 Type II audited, supports SSO and zero data retention, and signs DPAs and BAAs.

winfunc's evidence supports your assessment. Certification decisions remain with your auditor.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.