GROUND STATION · NITEROI ESTABLISHING UPLINK · UTC-3 TRACKING 12 OBJECTS ● LINK OPERATIONAL
000%
VINICIUS PEREIRA // GROUND CONTROL ALL SYSTEMS OPERATIONAL DSC 000% UTC-3 PROOF ↗
01ORBITAL VIEWNAV.HOME
OPERATOR: VINICIUS PEREIRA · NITEROI STATION · UTC-3 · CHANNEL OPEN TO US + EU

I BUILD AI
SYSTEMS THAT
SURVIVE PRODUCTIONTGT LOCK.

FULL-STACK AI ENGINEER · PROOF, NOT PROMISE
RETELL-SMS 66 CHECKS PASS  ·  TOKEN-LEDGER 32 CHECKS PASS  ·  JOB-ALERTS 39 CHECKS PASS  ·  LEAD-QUORUM 5 SERVICES LIVE ON CLOUD RUN  ·  GOOGLE CLOUD RUN BADGE AWARDED  ·  18 SECURITY DISCLOSURES · 3 ADVISORIES IN COORDINATION · BOUNTIES PAID BY ANTHROPIC AND MONGODB  ·  NOTHING SHIPS UNTESTED  ·  
◂ OPENING TRANSMISSIONWHO IS ON THE OTHER END
▶ 60-SECOND VISUAL BRIEFING · SOUND ON

I build AI automation and data pipelines that show their work and stay reliable in production. A multi-agent qualifier where two models cross-check each other and abstain when they disagree. An agent that writes SQL and corrects its own errors. A RAG pipeline that measures its retrieval quality before it answers. MCP servers that let an AI assistant query live business data mid-conversation.

Underneath all of it is the data craft that feeds every AI system: web scraping, PDF extraction, and Python pipelines that turn messy sources (websites, PDFs, public records, scattered APIs) into clean, structured data you can actually use.

All of it is public. Every claim on this page links back to its source: the repositories, a live app, published security advisories, a book you can download. Proof, not promise.

02TELEMETRYSYS.TLM
TLM-01
10+
YEARS IN DATA ENGINEERING
TLM-02
1,000+
BUSINESSES ON MY SAAS
TLM-03
5.0★★★★★
EVERY UPWORK CONTRACT
TLM-04
7
PUBLIC REPOS · TESTED + SHIPPED
TLM-05
18
SECURITY DISCLOSURES · 0 DISMISSED
TLM-06
$2,000
BUG BOUNTIES PAID BY ANTHROPIC AND MONGODB
03INSTRUMENTATIONTOOLCHAIN // 59 SYSTEMS
CORE07
PythonFastAPIPydanticpytestDjangoDjango REST FrameworkCelery
MODELS06
ClaudeChatGPTGeminiLlamaQwenMistral
RETRIEVAL & RAG06
LangChainHugging FaceChromaQdrantpgvectorBM25
AGENTS & PROTOCOLS05
LangGraphCrewAIGoogle ADKA2AMCP
LOCAL & INFERENCE03
OllamaLM StudioPyTorch
DATA & SCIENCE05
pandasNumPyscikit-learnJupyterPlotly
EXTRACTION & OCR06
PlaywrightSeleniumScrapyTesseract OCRn8nMake
APIS & COMMS05
StreamlitTwilioRetellOpenAPIAWS Rekognition
FULL-STACK WEB09
TypeScriptJavaScriptReactNext.jsVue.jsNode.jsViteCapacitorDeno
OPS & DEPLOY07
DockerGitHub ActionsVercelSupabaseSQLitePostgreSQLGoogle Cloud
04FLIGHT SYSTEMSOWNED · OPERATED
OWNED AND OPERATED BY THE ENGINEER · NOT CLIENT WORK
DeskCenter dashboard in English: point of sale, inventory and financials
FIG.02 · DESKCENTER · POS + INVENTORY + FINANCIALS
POS MODULE REAL-TIME INVENTORY FINANCIALS
SYS-A · DESKCENTER

RETAIL MANAGEMENT SAAS

A full retail platform: fast point of sale, real-time inventory, integrated financials, a public online catalog, and advanced reports (margin, ABC curve, sales projection). Reads an entire Excel workbook on import. The interface ships in English and Portuguese. Built, shipped and operated end to end.

ACTIVE BUSINESSES1,000+
ORDERS PROCESSED50K+
UPTIME99.9%
STACKTYPESCRIPT · REACT · SUPABASE · PWA
◂ VISIT DESKCENTER · LIVE IN ENGLISH →
SYS-B · 6-NA-REDE-IOS

6 NA REDE

LIVE ON THE APPLE APP STORE

The official app of a footvolley club in Niterói: training schedule with attendance, balanced doubles draw, win rankings, events and gallery. A Next.js PWA shipped as a native iOS app via Capacitor, one codebase through Apple review, published under my own developer name.

CATEGORYSPORTS · iOS APP STORE
DEVELOPERVINICIUS PEREIRA
STACKNEXT.JS 14 · TAILWIND · SUPABASE · CAPACITOR 8
◂ VIEW ON THE APP STORE →
6 na Rede app on the App Store
NATIVE SHELL
PWA CORE
RendaPerto English site: trusted help, right around the corner
FIG.03 · RENDAPERTO · TRUST-FIRST LOCAL SERVICES
FULL KYC BEFORE LISTING 3 REGISTRIES · AUTOMATED CLAUDE REQUEST PARSING
SYS-C · RENDAPERTO

TRUST-FIRST LOCAL SERVICES

LIVE · PILOT IN RESENDE, BRAZIL

A local-services marketplace for Brazil’s countryside towns: residents hire verified nearby workers for cleaning, small repairs and furniture assembly. Nobody appears in a search before passing full KYC: document capture, dual liveness selfies, automated face match against the document, and three criminal-record registries checked automatically, at under R$1 per verified worker. Requests typed or spoken in plain language are parsed by Claude. Automation flags, a human decides: the system never rejects anyone on its own. Privacy by design under LGPD: exact addresses and phone numbers never enter the system. Co-founded with the local founder who leads product; the entire technical build is mine.

VERIFICATIONDOC + LIVENESS + FACE MATCH + 3 REGISTRIES
COST PER VERIFIED WORKERUNDER R$1
STACKREACT · VITE · SUPABASE · CAPACITOR · AWS REKOGNITION
◂ VISIT RENDAPERTO.COM/EN →
05MISSION LOGCLIENT · NDA

CLIENT MISSIONS SHIP UNDER NDA. DESCRIBED BY OUTCOME, NOT BY NAME. QUOTES FROM PUBLIC REVIEWS OF COMPLETED CONTRACTS. ONE ENTRY IS A NAMED, PUBLIC COLLABORATION, NOT CLIENT WORK.

M-012026 · CLOSED 5.0 · SCHEDULER STILL LIVE

MARKET INTELLIGENCE PIPELINE

Daily scraping and enrichment for a US real-estate firm. Scheduler running 24/7 on a dedicated VPS, unattended.

★★★★★5.0His communication was excellent every step of the way.
M-022026 · CLOSED 5.0

CONFIG-DRIVEN CLEANSING ENGINE

Data cleansing driven entirely by configuration, backed by automated tests, so rules change without breaking pipelines.

★★★★★5.0Strong architecture, clear documentation, automated tests.
M-032026 · CLOSED 5.0

PROFESSIONAL REGISTRY EXTRACTION

Extraction and validation at scale: 7,010 validated records from a public physician registry, delivered clean and ahead of schedule.

★★★★★5.0Completed the work ahead of schedule and with accuracy. I would hire him again.
M-042026 · CLOSED 5.0

PRINT-VENDOR PRICING APIS

Six print vendors unified behind one pricing interface: a single contract over fragmented sources.

★★★★★5.0Clear, intelligent communication. Detail oriented.
M-052026 · CLOSED 5.0

MEDICAID FORM AUTOMATION

A manual government-form workflow automated end to end: fewer hands, fewer errors.

★★★★★5.0
M-062026 · CLOSED 5.0

LEGAL RESEARCH DATA COLLECTION

Two years of public forum discussion, 3,221 threads and 58,686 comments, delivered with a completeness report the client reconciled against the raw file himself.

★★★★★5.0Vinicius worked with me on focusing the project scope before carrying out seamlessly.
M-072026 · CLOSED 5.0

REGULATORY REGISTER MONITORING

A regulator's public licence registers monitored end to end: extraction, change detection, QA, recurring controls, and an independent handover.

★★★★★5.0Built with handover and maintainability in mind, rather than creating something dependent on him.
M-082026 · CLOSED 5.0

MEP COST ESTIMATION ENGINE

A custom costing engine for MEP estimation: masterdata, templates and quantity takeoffs resolved deterministically, reproducing the client's reference workbook to the cent, 111 of 111 rates.

★★★★★5.0Understood the requirements quickly, delivered fast, and handled every piece of feedback seriously. I would gladly work with him again.
REF2026 · NAMED CREDIT · arXiv

TRUSTWORTHY AGENTIC COMMERCE REVIEW

Invited technical reviewer on a decision-centered reference architecture for trustworthy agentic commerce by Dimitrios S. Sfyris, founder of AspectSoft, now published on arXiv. Credited by name for refining the separation between commercial eligibility and actor authority, the treatment of payment artifacts as evidence rather than automatic permission, and the controls that keep AI-generated claims grounded, scoped, and verifiable.

◂ READ THE PAPER ON arXiv →
06PAYLOADSOPEN SOURCE · MANIFEST
[01] SEQUENCE-GATEThe service a follow-up sequence asks before every send: stopping signals read before anything else so a contact who already replied is never chased, idempotency keyed on the case and step rather than the provider id, quiet hours on the contact's clock, and a ladder that has to end with a person · 138 tests. [02] GHL-BRIDGEPolicy-gated CRM automation: webhook idempotency keyed to the event, a gate that auto-sends only inside policy and parks the rest with the reason named, and a guard that raises if an unapproved send reaches the transport · 379 tests. [03] ON-BEHALFRetrieval where the authority over who opens a document stays with the source: every candidate is checked as the signed-in user at query time, and the ACL-snapshot index ships beside it, wrong by design, so the tests can prove the three leaks it opens · 353 tests. [04] TENANT-FENCEOne knowledge base, many customers: the entitlement filter runs before the candidate set is scored, so a leak needs the filter to be wrong instead of one caller to forget · 360 tests, 141 adversarial. [05] LANGGRAPH-PRODUCTIONThe reliability layer around a LangGraph agent: routing measured against labelled fixtures, a human gate before irreversible tools, and crash resume that pays a refund once · 373 tests. [06] LEAD-QUORUMMulti-agent orchestration that abstains when evidence is insufficient. Five services live on Cloud Run · Google badge. [07] BEDROCKNL-to-SQL agent with a stability harness, built for works-in-test-breaks-in-prod failures. [08] TOKEN-LEDGERLLM cost observability as a pip-installable product. CLI + zero-dependency dashboard · 32 tests. [09] RETELL-SMSVoice AI meets telephony: in-call SMS for Retell agents · 66 tests. [10] CROSSWATCHCross-source corroboration on a schedule: two providers confirm a row or it is excluded. [11] GROUNDING-PROBECounterfactual RAG eval: ablate the evidence, re-run, catch the answer that came from memory. [12] CONFIDENCE-GATEThe trust gate for LLM output before it reaches production: schema validation plus external confidence signals route each result to auto-accept, human review, or abstain · 112 tests. [13] MAKE-FAILSAFEError routing for Make scenarios that refuse to die silently: the visual flow routes, a tested decision service decides · 83 tests · verified live in a real workspace.
07ANOMALY REPORTSOFFENSIVE RESEARCH

THE OTHER HALF OF BUILDING SYSTEMS THAT SURVIVE PRODUCTION: FINDING THE CRACKS IN EVERYONE ELSE'S. REAL, EXPLOITABLE, WITH A WORKING PROOF OF CONCEPT. IF THE IMPACT CANNOT BE PROVEN, IT DOES NOT BECOME A REPORT.

PROTOCOL · SIX-PHASE AUDIT · EVALUATED AFTER EVERY STEP

Every audit runs the same sequence. Nothing advances on a hunch. The AI-augmented pipeline widens the reach; the judgment of what is real stays with me.

00
Qualify
Confirm scope, surface and what is actually worth attacking.
01
Map
Full recon: exposure, forgotten endpoints, fresh code, leaked secrets.
02
Enumerate
Every point where untrusted input meets a dangerous sink or a value flow.
03
Attack
Systematic battery per target: tamper, race, sequence, state, code sinks.
04
Confirm w/ Proof
Only what is executed and captured: real request/response, hash, timestamp, 3x repro.
05
Close Coverage
Every surface tested or justifiably untestable. No "good enough".
THREE STATES: SUSPECTED CONFIRMED· REFUTED · ONLY CONFIRMED SHIPS · ZERO FALSE POSITIVES
18
COORDINATED
DISCLOSURES
13
PROGRAMS
INCL. FRONTIER LABS
2/5/10/1
CRITHIGHMEDLOW
SEVERITY SPREAD
0
DISMISSED AS INVALID
EVERY REPORT A REAL FINDING
▸ 3 GITHUB SECURITY ADVISORIES IN COORDINATED DISCLOSURE · CREDITED ON THE RECORD · 2 BOUNTIES PAID · ANTHROPIC AND MONGODB
AR-01JUN 2026 · CONFIRMED + BOUNTY PAID

SECURITY VULNERABILITY · ANTHROPIC

Found and reported a security vulnerability to Anthropic through their official bug bounty program on HackerOne. Reproduced with a working proof of concept, triaged, and awarded a bounty. Reported responsibly before the change reached a released tag.

PROGRAMANTHROPIC SEVERITYMEDIUM · CVSS 5.9 BOUNTY$2,000 · PAID STATUSREWARDED
◂ TRANSMISSION RECEIVED · 2026-06-03SIGNAL VERIFIED
FROM: SECURITY TEAM · ANTHROPIC · RE: REPORT #3736738
"Thank you for this detailed report and the clear proof of concept. We are awarding a bounty of $2,000 for this finding based on its assessed severity (Medium, CVSS 5.9) and the affected asset. We appreciate you reporting this before the change reached the released tag."
◆ VALID◆ REWARDED $2,000◆ RESPONSIBLY DISCLOSED
QUOTE IS THE PROGRAM'S PUBLIC AWARD MESSAGE · TECHNICAL DETAILS OMITTED UNDER RESPONSIBLE DISCLOSURE
AR-022026 · COORDINATED DISCLOSURE · CREDITED

AUTHORIZATION BYPASS · DIRECTUS

Row-level authorization bypass in Directus, CWE-863. The GitHub Security Advisory is still in coordinated disclosure, and I am credited on it as a collaborator. The mechanism stays private until it ships.

PROGRAMDIRECTUS · OSS ADVISORYGHSA-X5CW-W9XM-77V2 SEVERITYMODERATE · CVSS 6.5 CLASSCWE-863 · AUTHZ
◂ ADVISORY LINK · PUBLIC ONCE IT SHIPS · VERIFY CREDIT →
AR-032026 · COORDINATED DISCLOSURE · CREDITED

SSRF · MCP INSPECTOR

Server-side request forgery in the official Model Context Protocol Inspector, reported by me. The GitHub Security Advisory is still in coordinated disclosure, so the mechanism stays private until it ships. Directly in the AI-agent supply-chain surface.

PROGRAMMCP INSPECTOR · OSS ADVISORYGHSA-55HW-XWFP-RHVC SEVERITYMODERATE · SSRF SURFACEAI-AGENT SUPPLY CHAIN
◂ ADVISORY LINK · PUBLIC ONCE IT SHIPS · VERIFY CREDIT →
AR-04SEP 2026 · ACCEPTED BY CANONICAL · CREDITED REPORTER

PATH TRAVERSAL · MULTIPASS

Path traversal in Multipass, the virtual machine manager by Canonical, on the recursive file transfer path: a transfer could write outside its destination directory on the host. Reported by me, accepted by Canonical in September 2026, with the fix landing in the next feature release. The GitHub Security Advisory names me as reporter and goes public with that release.

PROGRAMMULTIPASS · CANONICAL · OSS ADVISORYGHSA-PP54-9C8C-VP5G SEVERITYMEDIUM · CVSS 6.5 CLASSCWE-22 · PATH TRAVERSAL
◂ ADVISORY LINK · PUBLIC WITH THE FIX RELEASE · VERIFY CREDIT →
AR-05SEP 2026 · CONFIRMED + BOUNTY PAID

SECURITY VULNERABILITY · MONGODB

Found and reported a security vulnerability in Evergreen, MongoDB’s open-source CI platform, through MongoDB’s bug bounty program on HackerOne: an authenticated user holding no roles could make the platform act with its own credentials against targets of the user’s choosing. Reproduced three times in an isolated rig, with no request reaching GitHub or MongoDB infrastructure and every artefact hashed. Validated, rewarded and resolved by MongoDB’s security team in September 2026.

PROGRAMMONGODB · HACKERONE SEVERITYLOW · RESOLVED BOUNTY$100 · PAID CLASSCWE-610 · CONFUSED DEPUTY
◂ TRANSMISSION RECEIVED · 2026-09-11SIGNAL VERIFIED
FROM: SECURITY TEAM · MONGODB · RE: REPORT #3929762
"Thank you for your submission to MongoDB’s Bug Bounty Program. We are pleased to inform you that your report has been reviewed and validated by our security team, and we are happy to award a bounty for this issue. Your responsible disclosure helps us maintain the security of the MongoDB platform."
◂ FIXED UPSTREAM · NO ADVISORY ISSUED
A FINDING THAT NEVER BECAME AN ADVISORY, LISTED ANYWAY · IT SITS OUTSIDE THE REGISTER BELOW FOR EXACTLY THAT REASON
UP-01AUG 2026 · MERGED UPSTREAM

OUT-OF-BOUNDS READ · CRUN

crun is the OCI runtime Podman and CRI-O run containers with. Its passwd parser tested for a digit with **s - '0' < 10, a signed comparison with no lower bound, so 186 of the 256 possible byte values kept the loop running and the null terminator was one of them. A passwd line whose uid field is empty walks the parser past the end of the buffer. The correct form came from musl in June 2020 and lost its lower bound 43 minutes later, in a commit that dropped one character to silence a compiler warning on the Alpine build, which is where the affected path compiles. No advisory, no CVE, no severity assigned. It was fixed in the open as a correctness bug.

PROJECTCONTAINERS/CRUN · OSS STATUSMERGED BY MAINTAINER LIFETIME6 YEARS · 2020-2026 ADVISORYNONE ISSUED
◂ VIEW MERGED PULL REQUEST · VERIFY →
◂ DISCLOSURE REGISTRY · 17 VALIDATED FINDINGS
RESOLVED AND PUBLISHED FINDINGS NAMED · UNRESOLVED ONES ANONYMIZED UNTIL THEY SHIP · ◆ = PUBLISHED ADVISORY
AR-01ANTHROPICArbitrary file read via PR-controlled symlink · CWE-22 · bounty paidMEDIUM · 5.9
AR-02DIRECTUSRow-level authorization bypass · CWE-863 · credited collaborator · advisory in coordinationMODERATE · 6.5
AR-03MCP INSPECTORPost-auth SSRF · reported by me · advisory in coordinationMODERATE
AR-04MULTIPASS · CANONICALPath traversal in recursive file transfer · CWE-22 · accepted, credited reporter · advisory publishes with the fixMEDIUM · 6.5
AR-05MONGODBCredentialed write aimed by an unprivileged user · CWE-610 · bounty paidLOW · RESOLVED
AR-06API GATEWAY · OSSRCE via script sandbox escape · constructor bypassCRITICAL
AR-07FRONTIER AI LABArbitrary OS command exec via untrusted MCP server configHIGH
AR-08WEB FRAMEWORK · OSSMiddleware auth bypass · incomplete-fix of a prior CVEHIGH
AR-09API GATEWAY · OSSRCE · trust-grant bypass of the STDIO safety modalHIGH
AR-10ID-VERIFICATION VENDORUnauthenticated cross-tenant disclosure of ID-verification sessionsHIGH
AR-11AUDIO STREAMING PLATFORMCross-entity authorization bypass via path traversalMEDIUM
AR-12DATABASE PLATFORM · OSSArbitrary file write via path traversal · zip-slipMEDIUM
AR-13ID-VERIFICATION VENDORLive analytics write-keys disclosed · arbitrary event injectionMEDIUM
AR-14DIGITAL BANKUnrestricted API key + backend surface via public runtime configMEDIUM
AR-15DIGITAL BANKPublic S3 bucket listing · 830 objects enumerableMEDIUM
AR-16EMBEDDED TLS / CRYPTO STACKOut-of-bounds read in ECC public-key parsingMEDIUM
AR-17CONTAINER ORCHESTRATION CLIENT · OSSTLS hostname validation bypass in custom-CA mode · bearer token sent to a mismatched serverHIGH · 7.4
AR-18DATABASE KUBERNETES OPERATOR · OSSCross-namespace privilege escalation via unvalidated resource reference · operator provisions root on another tenantCRITICAL · 9.6
TARGETS SPAN FRONTIER AI LABS, DEVELOPER PLATFORMS, IDENTITY AND FINTECH · WHITEBOX SOURCE AUDIT, BUSINESS-LOGIC, RECON AND AI/LLM SURFACES · TRACK RECORD: NO REPORT DISMISSED AS INVALID
08FIELD MANUALAUTHORED · 84 PAGES
Artificial Intelligence in Practice, book cover by Vinicius Pereira
PUB-01 · WRITTEN + PUBLISHED · FREE

ARTIFICIAL INTELLIGENCE IN PRACTICE

A free 84-page handbook on applied AI, written for developers who want to build with LLMs instead of just reading about them. Everything in it was tested by hand: from "what is a token" all the way to a working agent with tools, and what it costs to run.

◦ FOUNDATIONS◦ LOCAL MODELS◦ RAG◦ AGENTS◦ FINE-TUNING & COST◦ SECURITY◦ EVALUATION◦ 3 CAPSTONE PROJECTS
OLLAMA · QWEN · LLAMA · CREWAI · LANGGRAPH · MCP · CLAUDE
10OPERATOR FILEDOSSIER
OPERATORVINICIUS PEREIRA
STATIONNITEROI, BRAZIL · UTC-3
DISCIPLINEFULL-STACK AI ENGINEER
METHODWRITTEN-FIRST · AUDITABLE
SECURITY17 DISCLOSURES · ANTHROPIC PAID · CRUN FIX MERGED
STATUS● OPERATIONAL

A decade building data platforms inside one of Latin America's largest credit bureaus and two global consulting firms. On my own time, I ship products people pay for.

I work written-first: scope agreed in writing, decisions documented, delivery you can audit. The proof is on this page: running systems, tests that pass, contracts that closed at five stars.

◂ CREDENTIALS · ACCREDITATION · ALL VERIFIABLE
GOOGLE CLOUD RUN BADGE ANTHROPIC BUG BOUNTY · PAID 3 GITHUB ADVISORIES IN COORDINATION APPLE APP STORE · DEVELOPER AUTHOR · 84-PAGE AI HANDBOOK 5.0 ON EVERY UPWORK CONTRACT
11OPEN A CHANNELCONTACT
BROADCAST FREQUENCY · REPLY GUARANTEED
hello@vinimabreu.dev

One transmission is enough: what you need, where the data lives, what done looks like. I reply with questions or a plan, in writing.

© 2026 · BUILT WITH NEXT.JS · DEPLOYED ON VERCEL NITEROI GROUND STATION · BRAZIL ● OPERATIONAL