Consumer-first security research
Our goal is not notoriety — it is visible, accountable systems. Every scan and disclosure on this site follows a strict, repeatable ethical framework so the findings are useful to regulators and defensible in public.
Principles
Read-only, always
Only passive GET requests to discover exposed content. No authentication bypass, no exploitation, no data exfiltration, no destructive tests.
No PII, ever
We never republish personal data from a leak or a scan. Only key names, lengths, paths and metadata are recorded. Credential values are deliberately not stored.
Evidence-led
Every substantive claim is traceable to a probe result or crawl record. Aggregates are recomputable from published CSVs and scripts.
Responsible disclosure
Findings go to CERT-In, RBI and affected institutions before any public post. We publish the class of exposure and the disclosure record so the whole sector can fix the pattern.
Disclosure workflow
- Confirm the exposure with repeated, independent checks (often across days).
- Report to CERT-In (incident@cert-in.org.in) and the affected entity's registered security/IT contacts.
- Track remediation — re-scan to confirm the file is removed, not merely hidden behind a WAF.
- Correct ourselves — if a claim doesn't hold up under scrutiny (as with the Jana Small Finance Bank .env claim), we retract and correct it publicly and in the disclosure thread.
- Publish the anonymised analysis only after disclosure to regulators.
Limitations we state
Scanner result counts are point-in-time; environments change. Metadata-level leak analysis cannot speak to the actual contents of dumped files, only what file names and paths indicate. We say this plainly on every investigation page, and we encourage independent verification.
Agentic production: how this work is run
This is agentic cyber work. The scans, crawls, leak-catalogue analysis and page drafting on this site are carried out by AI agents running on Zo Computer — a personal server — predominantly on the DeepSeek V4 Flash model. We say this plainly because readers deserve to know exactly what kind of machine produced a finding, and how much human judgement sits behind it.
Machine (agent): discovery, scan orchestration, log parsing, aggregate computation, file triage and first-draft wording. It runs continuously and covers far more ground than a human could.
Human (us): targeting decisions, ethics review, verification of every substantive claim, disclosure to CERT-In and affected institutions, and the final call on what gets published. Nothing ships without a human signing off.
Supervision is not an afterthought — it is the control plane. Scan scopes are human-defined and read-only. Findings are reviewed against raw evidence before disclosure. When a model artefacts a claim — as in the Jana Small Finance Bank .env correction earlier on this page — we catch and retract it publicly rather than let automation stand on automation.
A note on the .net stack
This site is a plain, dependency-free static build — HTML, CSS and a small JS file. No trackers, no analytics, no third-party fonts. It is hosted on GitHub Pages and served from our own domain.