For Supabase apps built with Lovable · Bolt · v0 · Replit · Cursor
READ-SAFEAUTHORIZED-ONLYNO WRITES

Someone could be reading your whole database right now.

One public key is all it takes. We prove exactly what an attacker can reach — read-safe — and give you the RLS policy that shuts it.

Cross-account IDORMissing RLS on tablesService-role token in the browserLeaked Stripe / service_role keysMissing security headersNext.js auth bypass (CVE)Subdomain takeoverVulnerable deps (live OSV match)GDPR / DPDP exposure
How it works

Other scanners tell you it's broken. This one hands you the patch.

The scan runs in the order an attacker would work, and every step produces something you can act on.

01

Probe

We hit your Supabase REST endpoint with the anon key the way any stranger can: read, insert, update, delete, on every table we can find.

02

Prove

Destructive probes use filters that can never match a row, so a 204 proves the policy is missing without touching a single record.

03

Patch

For each finding you get the specific RLS policy or auth setting — written for your table and your columns, not a generic snippet.

What we scan for

Every check is accounted for against your live app.

Every report shows the full matrix. Executed checks include their evidence; unavailable prerequisites and coverage gaps are shown explicitly and never counted as passes.

105 checks·10 categories
01

Access control & IDOR

11 checks
Cross-account IDOR (capture & replay)Unauthenticated data leak (replay as anon)Read IDOR / BOLAWrite IDOR (cross-tenant)Cross-tenant write (canary-proven)Mass assignmentSelf-escalation via privileged profile fieldsAdmin endpoints reachable by a low-privilege user (BFLA)RPC IDOR (function leaks by id)Tautological RLS (not owner-scoped)Admin endpoint without login (BFLA)
02

Database & RLS

14 checks
Anonymous table readPII / sensitive column exposureMissing write-side RLS (insert)Missing write-side RLS (storage upload)Schema disclosure (PostgREST OpenAPI)auth.users exposed (emails + hashes)SECURITY DEFINER / dangerous RPCAnon-executable RPCSQL injection in DB functionspg_graphql anonymous readpg_graphql introspectionInternal schema exposed — authInternal schema exposed — vaultInternal schema exposed — extensions
03

Auth & crypto

12 checks
JWT weak / default signing secretJWT alg=none acceptanceService-role token in the browserLong-lived / non-expiring tokensMetadata privilege escalationEmail verification disabledPhone verification disabledOpen signup exposureRisky external auth providersWeak password policyOpen redirect on auth serviceAuth rate limiting
04

Secrets & exposed code

20 checks
Supabase service_role key in bundleSupabase secret key (sb_secret_)Stripe secret key (sk_live / sk_test)Stripe webhook secret (whsec_)AWS access key (AKIA)OpenAI API keyAnthropic API keyGitHub tokenGoogle API key (AIza)Firebase config leakPrivate key blocks in bundleProven service_role RLS bypassExposed .envExposed .git / .sqlBackup / dump files (.bak · .sql)API docs / Swagger exposedGraphQL introspection enabledSource maps with source contentExposed manifests / lockfilesvercel.json exposed
05

Config & headers

17 checks
Content-Security-PolicyStrict-Transport-Security (HSTS)X-Frame-Options (clickjacking)X-Content-Type-OptionsReferrer-PolicyPermissions-PolicyHTTPS & transportLegacy TLS (1.0 / 1.1) acceptedCookie Secure flagCookie HttpOnly flagCookie SameSite flagSubresource Integrity (SRI)Cacheable auth responsesecurity.txt (RFC 9116)Open / wildcard CORSCORS reflected credentialsDev endpoints live in prod
06

Platform & edge

09 checks
Next.js middleware auth bypass (CVE-2025-29927)Next.js RSC / transport bypass cluster (2026)Dynamic-route param bypass (CVE-2026-44574)Edge Function callable without authSSRF in edge functionsStripe webhook signature forgeryStorage — private bucket downloadableStorage — private bucket listableStorage — public bucket, private files
07

Payment integrity

03 checks
Payment webhook signature forgery (any provider)Client-controlled charge amount (price tampering)Payment confirmation replay (no idempotency key)
08

Attack surface

05 checks
Subdomain enumeration (CT logs)Subdomain takeover (dangling CNAME)Stack fingerprintingSPF record (email spoofing)DMARC policy
09

Known CVEs & vulnerable deps

07 checks
Exact-version fingerprint (source maps + bundle)Next.js CVEs (live OSV match)React / react-dom CVEs@supabase/* library CVEsSupabase Auth (GoTrue) CVEsRSC deserialization RCE (version-flagged)Vulnerable transitive dependencies
10

Compliance mapping

07 checks
GDPR Art. 32 (security of processing)GDPR Art. 33 (breach exposure)India DPDP (2025)Lawful-basis reviewPCI-DSS surfaceHIPAACCPA

Compliance findings are derived from exposures we prove — a practical interpretation, not legal advice. Cross-account checks (IDOR, cross-tenant writes, privilege escalation) run when you connect a second test account.

Deep audit

Watch the models argue.

Surface scanners catch the obvious. The deep audit runs a panel of models that audit independently, cross-examine each other, and let a judge adjudicate — grounded by read-safe probes as ground truth. Chained, non-obvious issues surface where single-tool scanners go quiet.

Run a deep audit
$ deep-audit myapp.com
▸ 3 models auditing independently…
▸ deterministic probe → ground truth
▸ cross-examination: 4 of 6 refuted
✓ judge: 2 confirmed + 1 proof
final grade A · 94/100
Pricing

See what an attacker can reach — from $19.

Start at $19/month, or run a $29 one-time pack of three authenticated deep audits — real findings, proved read-safe, each with its exact fix.

Go · monthly
$19/month

For apps you keep shipping — a fresh audit every time you deploy.

  • — 4 authenticated deep audits / month
  • — Every fix unredacted + AI-tool export
  • — Re-scan to verify each fix
  • — Up to 3 projects
Start with Go
Starter · most popular
$29one-time

Three authenticated deep audits with fixes. No subscription — try it once.

  • — 3 authenticated deep audits
  • — Every fix unredacted + AI-tool export
  • — Re-scan to verify each fix
Get the pack
Pro
$39/month

Automated coverage + monitoring, for apps with real users.

  • — 12 deep audits / month
  • — Weekly automated audit
  • — Monitoring + email alerts
  • — RGS-Protected badge · up to 10 projects
Go Pro