Skip to content
winfunc
Vulnerability management

From finding to verified fix, without the queue.

Connect evidence, triage, remediation, and verification in one workflow, so every finding moves toward a decision.

What's included
  1. acme
  2. /billing-api
  3. /Vulnerabilities
Search findingsStatus Open
42 open
SeverityFinding
C9.1
Cross-tenant invoice read through an unscoped lookupAccess controlservices/invoices.ts:42
H8.1
Admin export reachable without a role checkAuthorizationroutes/admin/export.ts:18
H7.5
Webhook preview fetches internal addressesSSRFwebhooks/preview.ts:61
M6.5
Refresh token accepted without an audience checkAuthenticationauth/refresh.ts:27
M5.4
Stored XSS in the invoice memo rendererXSSweb/Memo.tsx:14
L3.1
Stack trace returned on malformed CSV importExposureimports/csv.ts:90
VulnerabilitiesIllustrative data
The problem

Backlogs grow when nobody can tell what is real.

A finding without evidence is a debate. winfunc attaches the trace and the proof, deduplicates across scans, prepares the patch, and re-checks it after the change. Findings close because they are fixed, not because they aged out.

Included

What winfunc covers.

  • Finding states from pending to validated, accepted, and resolved
  • Repository-aware triage with evidence and open questions
  • Duplicate detection with similarity scoring across scans
  • Filtering by severity, confidence, status, and revision
  • Bulk review and exports
  • Suggested patches opened as pull requests
  • Validation and revalidation after remediation
  • Security scores, hotspots, and trends per repository
Outcomes

What your team walks away with.

01

Structured triage

States and review notes record what was investigated, what evidence existed, and what your team decided.

02

AI-assisted investigation

The security assistant explores prerequisites, affected paths, and impact with your team, citing the code as it goes.

03

Deduplication

Similarity signals connect related findings across scans so one root cause gets one fix.

04

Verified closure

Revalidation confirms the exploit path is closed before a finding is marked resolved.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.