One public key is all it takes. We prove exactly what an attacker can reach — read-safe — and give you the RLS policy that shuts it.
The scan runs in the order an attacker would work, and every step produces something you can act on.
We hit your Supabase REST endpoint with the anon key the way any stranger can: read, insert, update, delete, on every table we can find.
Destructive probes use filters that can never match a row, so a 204 proves the policy is missing without touching a single record.
For each finding you get the specific RLS policy or auth setting — written for your table and your columns, not a generic snippet.
Every report shows the full matrix. Executed checks include their evidence; unavailable prerequisites and coverage gaps are shown explicitly and never counted as passes.
Compliance findings are derived from exposures we prove — a practical interpretation, not legal advice. Cross-account checks (IDOR, cross-tenant writes, privilege escalation) run when you connect a second test account.
Surface scanners catch the obvious. The deep audit runs a panel of models that audit independently, cross-examine each other, and let a judge adjudicate — grounded by read-safe probes as ground truth. Chained, non-obvious issues surface where single-tool scanners go quiet.
Run a deep auditStart at $19/month, or run a $29 one-time pack of three authenticated deep audits — real findings, proved read-safe, each with its exact fix.
For apps you keep shipping — a fresh audit every time you deploy.
Three authenticated deep audits with fixes. No subscription — try it once.
Automated coverage + monitoring, for apps with real users.