Supabase Security Audit

Security Audit for Supabase Apps

Supabase lets the browser talk to Postgres directly, which is exactly why row-level security is your real security boundary. Lovable, Bolt, Cursor, and other AI tools wire up Supabase quickly. We check that every table, function, and bucket enforces the rules your product needs.

30-minute intro call · fixed-scope quote · human review, not scanner output. Read client case studies.

What we find most often in Supabase projects

Supabase's security model is sound when configured correctly. Problems come from policies written during fast iteration and never revisited.

RLS disabled or overly permissive

Tables without RLS, or with policies such as `using (true)`, are readable or writable by anyone with the public anon key, which ships in your front end by design.

Service role key in the wrong place

The service role key bypasses RLS entirely. If it appears in client code, a public repo, or a loosely protected function, every row in the database is exposed.

Security definer functions without checks

Database functions marked `security definer` run with the owner's privileges. Exposed through the API without their own authorization checks, they can bypass RLS.

Policies that trust user-editable data

Policies that read roles or tenant IDs from `user_metadata` can be bypassed, because users can update their own metadata. Authorization data must come from a source users cannot change.

Storage buckets and policies

Public buckets or broad storage policies can expose uploaded documents, invoices, and private images to anyone who knows or guesses the path.

Edge functions skipping verification

Edge functions that use the service role key must verify the caller's JWT and ownership before acting, or they become a bypass around your policies.

What a Supabase security audit covers

A fixed-scope review of your Supabase schema, policies, functions, and storage, plus the app code that calls them.

RLS policy review for every table in exposed schemas
Two-account access testing against the live API using the anon key
Service role key usage review across client, server, and functions
Database function review, including security definer functions
Storage bucket visibility and storage policy review
Edge function review: JWT verification, ownership checks, input validation
Review of Security Advisor findings with context on which matter
Prioritized report with severity, reproduction steps, and corrected SQL policies

Checks you can run yourself

Start here before you book anything. If any of these fail or you are not sure how to check, that is the signal to get a second pair of eyes.

  • Run the Security Advisor in your Supabase dashboard and resolve every RLS-related warning.
  • Search your front-end code and repo history for the service role key and rotate it if found.
  • Review every policy that uses `true` or reads from `user_metadata`.
  • List functions marked `security definer` and confirm each checks the caller's identity.
  • Confirm private files live in private buckets with policies scoped to their owner.

Want a scored version? Take the free vibe code security check or work through the 25-point launch checklist.

Frequently asked questions

Running on Supabase?

Book a free 30-minute call. We will review your project setup, scope the audit, and send a fixed quote.