Proof · A paid work task
Find the holes in Proof before someone else does.
Go through Proof like someone trying to get in, or see data that isn’t theirs. Document each real vulnerability precisely enough that I can hand it straight to a fix.
The promise · ₹1,000
₹1,000 for a careful, honest audit — paid for verified findings you can show me how to reproduce, whether or not I act on every one. It’s work, not a hiring promise.
● OPEN — no deadline. It stays open until this line says otherwise.
First · sign in to start
This is paid work with your name on the record, so you sign in first — one tap with Google.
Sign in →The work
Each finding =
Four lines:Where — the exact screen / URL / request
What’s exposed— the data or action that shouldn’t be reachable
Reproduce — the steps, so I can see it too
Why it matters— who gets hurt if it’s left
Before you start
Scope
Only proof.zeromaintenanceengineer.in and your own accounts. Don’t touch other people’s data, don’t run load/DoS tests, don’t break the live service for anyone else.
It’s a web app
A Next.js app in the browser — so an intercepting proxy (Burp, ZAP), the request tab, and your own two accounts are the tools that find things here. There is no shipped mobile build, so an APK/IPA scanner like MobSF has nothing to scan. Auth, access between accounts, and what one account can reach of another’s is where the real holes have been.
Verify before you file
Reproduce each finding yourself first. A guess you haven’t confirmed is noise — “it works” has to mean it works.
Keep it private
File each hole with 🔥 Roast Proof → 🔒 Security hole, never in public. Security reports stay private until I fix them — the details never show on the public Reports tab.
You agree
Sign first
You read and sign the Zero Maintenance Engineer manifestobefore you start — it’s the standard the work is held to.
Paid for the work
₹1,000 for honest, verified auditing — whether or not I act on each finding. No finding is a promise of a job.
Your record
Each finding
counts on your Proof record the moment you file it — yours, you carry it anywhere — and every fix I ship from it,
I credit you by name on
Reports (without the exploit details).
One round
You’ll take one round of feedback — I sharpen your first two findings, you adjust the rest.
Done =
Count
At least 5distinct, reproducible findings (a mix of severities is fine — a real low-severity issue beats an unverified “critical”).
Format
Each one = Where / What’s exposed / Reproduce / Why it matters.
Reproducible
Clear enough that I can follow your steps and see the flaw myself with no extra questions.