# winfunc

> winfunc (formerly Asterisk, YC S24) is an AI-native security engineering platform that behaves like an autonomous hacker: it finds, verifies, and patches vulnerabilities in codebases. Instead of dumping thousands of unverified SAST alerts on engineers, winfunc spins up sandboxes, writes working proof-of-concept exploits, and only reports bugs it can actually trigger - aiming for near-zero false positives. Its agent has surfaced real vulnerabilities in Node.js, React, NGINX, Supabase, Bun, Sentry, Gumroad, Anthropic's MCP SDK, and others. Founded by Mufeed VH and Vivek R, the team previously built Devika, a popular open-source AI software engineer.

- **Founded:** 2024
- **Headquarters:** San Francisco, California, United States
- **Founders:** Mufeed VH (Co-founder & CEO), Vivek R (Co-founder & CTO)
- **Team size:** 2 (at time of profiling)
- **Products:** Vulnerability Detection, Sandbox Verification, AI-Generated Patches, PR Security Scanning, Dependency Scanning
- **Notable:** Accepted into Y Combinator Summer 2024 batch (launched as Asterisk, later rebranded winfunc)., Agent found and helped patch real vulnerabilities across major projects including Node.js, React, NGINX, Supabase, Bun, Gumroad, Better-Auth, Mattermost, and Anthropic's MCP SDK., Founders previously built Devika, an open-source alternative to Devin with 18,000+ GitHub stars.

## Products & services

- **Vulnerability Detection** — Multi-phase static analysis with source-to-sink tracking, tree-sitter queries, and LLM-powered code comprehension; produces executable proof-of-concept exploits and detects both traditional bugs (SQLi, XSS) and business-logic flaws.
- **Sandbox Verification** — Spins up a sandbox, runs the target software, and attempts to exploit each finding so only confirmed, reproducible vulnerabilities are reported - the core of its near-zero-false-positive claim.
- **AI-Generated Patches** — Autonomously generates fixes and delivers them as pull requests.
- **PR Security Scanning** — Scans every pull request for vulnerabilities before it reaches production, enabling continuous auditing on each commit.
- **Dependency Scanning** — Continuous software composition analysis across ecosystems to surface vulnerable dependencies.
- **AI Security Assistant** — Context-aware triage and prioritization of findings for security teams.
- **Dome** — Security policies expressed as a type system with build-time enforcement, a runtime proxy, and kernel sandboxing.

## Achievements

- Accepted into Y Combinator Summer 2024 batch (launched as Asterisk, later rebranded winfunc).
- Agent found and helped patch real vulnerabilities across major projects including Node.js, React, NGINX, Supabase, Bun, Gumroad, Better-Auth, Mattermost, and Anthropic's MCP SDK.
- Founders previously built Devika, an open-source alternative to Devin with 18,000+ GitHub stars.
- SOC 2 certified with a public Trust Center.
- Supports an unusually broad language set including Haskell, Elixir, Clojure, Lua, and niche languages.

## Latest updates

- **2024-08** — Launched as Asterisk in Y Combinator's S24 batch; publicized agent findings across major open-source projects.
- **2025** — Rebranded from Asterisk to winfunc; expanded platform with PR scanning, dependency scanning, AI patches, and the Dome policy-as-type-system module.

## Links

- Website: https://winfunc.com
- LinkedIn: https://www.linkedin.com/company/winfunc
- Twitter/X: https://x.com/winfunc
- GitHub: https://github.com/winfunc

---

Profile page: https://yespress.io/winfunc-yc-s24
Published by YesPress — https://yespress.io
Last updated: 2026-07-30
