cyber.cashlessconsumer.in
Agentic work Human-supervised AI on Zo Computer ▸ what this means

Everything on this site is agentic cyber work: AI agents running on Zo Computer plan the probes, execute read-only scans, analyse the results and draft the findings — predominantly on DeepSeek V4 Flash. A human steers and monitors every stage. No scan runs, no finding is disclosed and no text is published without human review and sign-off.

The machine does the legwork at speed and scale; the intent, the ethics and the accountability are human.

cyber / method & ethics
⚖️ How we work

Consumer-first security research

Our goal is not notoriety — it is visible, accountable systems. Every scan and disclosure on this site follows a strict, repeatable ethical framework so the findings are useful to regulators and defensible in public.

Principles

Read-only, always

Only passive GET requests to discover exposed content. No authentication bypass, no exploitation, no data exfiltration, no destructive tests.

No PII, ever

We never republish personal data from a leak or a scan. Only key names, lengths, paths and metadata are recorded. Credential values are deliberately not stored.

Evidence-led

Every substantive claim is traceable to a probe result or crawl record. Aggregates are recomputable from published CSVs and scripts.

Responsible disclosure

Findings go to CERT-In, RBI and affected institutions before any public post. We publish the class of exposure and the disclosure record so the whole sector can fix the pattern.

Disclosure workflow

  1. Confirm the exposure with repeated, independent checks (often across days).
  2. Report to CERT-In (incident@cert-in.org.in) and the affected entity's registered security/IT contacts.
  3. Track remediation — re-scan to confirm the file is removed, not merely hidden behind a WAF.
  4. Correct ourselves — if a claim doesn't hold up under scrutiny (as with the Jana Small Finance Bank .env claim), we retract and correct it publicly and in the disclosure thread.
  5. Publish the anonymised analysis only after disclosure to regulators.

Limitations we state

Scanner result counts are point-in-time; environments change. Metadata-level leak analysis cannot speak to the actual contents of dumped files, only what file names and paths indicate. We say this plainly on every investigation page, and we encourage independent verification.

Agentic production: how this work is run

This is agentic cyber work. The scans, crawls, leak-catalogue analysis and page drafting on this site are carried out by AI agents running on Zo Computer — a personal server — predominantly on the DeepSeek V4 Flash model. We say this plainly because readers deserve to know exactly what kind of machine produced a finding, and how much human judgement sits behind it.

Division of labour

Machine (agent): discovery, scan orchestration, log parsing, aggregate computation, file triage and first-draft wording. It runs continuously and covers far more ground than a human could.

Human (us): targeting decisions, ethics review, verification of every substantive claim, disclosure to CERT-In and affected institutions, and the final call on what gets published. Nothing ships without a human signing off.

Supervision is not an afterthought — it is the control plane. Scan scopes are human-defined and read-only. Findings are reviewed against raw evidence before disclosure. When a model artefacts a claim — as in the Jana Small Finance Bank .env correction earlier on this page — we catch and retract it publicly rather than let automation stand on automation.

A note on the .net stack

This site is a plain, dependency-free static build — HTML, CSS and a small JS file. No trackers, no analytics, no third-party fonts. It is hosted on GitHub Pages and served from our own domain.