Structured triage
States and review notes record what was investigated, what evidence existed, and what your team decided.
Connect evidence, triage, remediation, and verification in one workflow, so every finding moves toward a decision.
| Severity | Finding |
|---|---|
| C9.1 | Cross-tenant invoice read through an unscoped lookupAccess controlservices/invoices.ts:42 |
| H8.1 | Admin export reachable without a role checkAuthorizationroutes/admin/export.ts:18 |
| H7.5 | Webhook preview fetches internal addressesSSRFwebhooks/preview.ts:61 |
| M6.5 | Refresh token accepted without an audience checkAuthenticationauth/refresh.ts:27 |
| M5.4 | Stored XSS in the invoice memo rendererXSSweb/Memo.tsx:14 |
| L3.1 | Stack trace returned on malformed CSV importExposureimports/csv.ts:90 |
A finding without evidence is a debate. winfunc attaches the trace and the proof, deduplicates across scans, prepares the patch, and re-checks it after the change. Findings close because they are fixed, not because they aged out.
States and review notes record what was investigated, what evidence existed, and what your team decided.
The security assistant explores prerequisites, affected paths, and impact with your team, citing the code as it goes.
Similarity signals connect related findings across scans so one root cause gets one fix.
Revalidation confirms the exploit path is closed before a finding is marked resolved.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.