NewN-Day-BenchLearn more
winfunc

Trust Center

Security is our product. Here's how we protect your code, your data, and your trust.

AICPASOC 2TYPE IICertified

SOC 2 Type II

Independently audited controls for security, availability, and confidentiality. Covers all production systems and customer data handling.

In Progress

ISO 27001

Information security management system certification. Formalizes our existing security controls into the ISO framework.

Enterprise-Grade Security

Purpose-built for organizations with strict security and compliance requirements.

Self-Hosted Deployment

Deploy winfunc entirely within your own infrastructure — on-premises or private cloud. Full control over data residency, network isolation, and access policies. No data ever leaves your perimeter.

Zero Data Retention (ZDR)

Source code is processed in memory and discarded immediately after analysis. Only metadata (findings, severity, line numbers) is retained. Your code never touches our storage layer.

Dedicated Support & SLA

Enterprise plans include a dedicated security engineer, priority Slack channel, guaranteed response times (< 1 hour for critical issues), and quarterly security reviews.

Role-Based Access Control

Granular RBAC with SSO/SAML integration. Control who can view findings, approve patches, and manage scan configurations. Full audit trail of all user actions.

Data Handling

How we process, encrypt, and store your data at every layer.

Encryption at Rest

All data encrypted with AES-256. Customer-managed encryption keys (CMEK) available for Enterprise plans.

Encryption in Transit

TLS 1.3 for all connections. Certificate pinning enforced for API communications.

Key Management

Keys rotated automatically. HSM-backed key storage. Customer-managed keys supported via AWS KMS or GCP Cloud KMS.

Data Residency

Choose where your data is processed and stored. Available regions: US, EU, APAC. Self-hosted option for complete control.

Architecture Overview

Your Code
GitHub / GitLab / Self-Hosted
Winfunc Scanner
Isolated Analysis Environment
Findings Only
Zero Source Code Retained

Service Level Agreements

Our commitments to uptime, response times, and service delivery.

MetricStandardEnterprise
Platform Uptime99.9%99.99%
Critical Issue Response< 4 hours< 1 hour
High Issue Response< 8 hours< 4 hours
Scan Completion (avg)< 30 minutes< 15 minutes
Security Patch DeliveryBest effort< 24 hours

View our full audit reports and compliance documentation

Visit Trust Portal