Security Audit for Supabase Apps
Supabase lets the browser talk to Postgres directly, which is exactly why row-level security is your real security boundary. Lovable, Bolt, Cursor, and other AI tools wire up Supabase quickly. We check that every table, function, and bucket enforces the rules your product needs.
30-minute intro call · fixed-scope quote · human review, not scanner output. Read client case studies.
What we find most often in Supabase projects
Supabase's security model is sound when configured correctly. Problems come from policies written during fast iteration and never revisited.
RLS disabled or overly permissive
Tables without RLS, or with policies such as `using (true)`, are readable or writable by anyone with the public anon key, which ships in your front end by design.
Service role key in the wrong place
The service role key bypasses RLS entirely. If it appears in client code, a public repo, or a loosely protected function, every row in the database is exposed.
Security definer functions without checks
Database functions marked `security definer` run with the owner's privileges. Exposed through the API without their own authorization checks, they can bypass RLS.
Policies that trust user-editable data
Policies that read roles or tenant IDs from `user_metadata` can be bypassed, because users can update their own metadata. Authorization data must come from a source users cannot change.
Storage buckets and policies
Public buckets or broad storage policies can expose uploaded documents, invoices, and private images to anyone who knows or guesses the path.
Edge functions skipping verification
Edge functions that use the service role key must verify the caller's JWT and ownership before acting, or they become a bypass around your policies.
What a Supabase security audit covers
A fixed-scope review of your Supabase schema, policies, functions, and storage, plus the app code that calls them.
Checks you can run yourself
Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.
- Run the Security Advisor in your Supabase dashboard and resolve every RLS-related warning.
- Search your front-end code and repo history for the service role key and rotate it if found.
- Review every policy that uses `true` or reads from `user_metadata`.
- List functions marked `security definer` and confirm each checks the caller's identity.
- Confirm private files live in private buckets with policies scoped to their owner.
Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.