Prove your row-level security actually isolates tenants.
Most Supabase data leaks are not exotic. They are a table with RLS switched off, a policy keyed on a claim the user can edit, or a view that quietly serves rows past the policy. We audit that configuration and prove tenant isolation at the database, then commit the test that keeps it proven.
rls-audit
A command-line auditor for Postgres and Supabase row-level security. It connects to the database URL you give it and prints to your terminal. No account, no upload, no telemetry. Apache-2.0, and not yet published. When it is, the install line and the repository appear here together.
A clean scan is necessary but not sufficient. The catalogue cannot prove a policy’s logic is right, only that the guard rails are there. The isolation probes prove the logic.
Authorized RLS and Auth Isolation Configuration Review
A fixed-scope review, delivered within 48 hours of the review starting, once you have signed the authorisation and provisioned a staging or branch database clone. We run one engagement at a time, so we agree a start date rather than promise an instant one. It is a configuration review and isolation test. It is not a penetration test.
Fixed scope, fixed fee.
All prices in Australian dollars. Any GST that applies is shown on the invoice. Invoiced through Xero and paid by bank transfer.
The faults that leak Supabase data.
What a clean result does and does not mean.
- We check the row-level security and auth-isolation configuration of the schemas we agree, and we prove tenant isolation at the database layer. That is the whole of it.
- We do not test your application code, your API gateway, or anything above the database. We are not a penetration test and do not claim to be.
- A clean result is evidence about the tables and policies we saw, at the time we saw them. It is not a guarantee that your application is secure.
- A signed authorisation comes before any access. You can withdraw it in writing at any time.
- Our total liability is capped at the fees you pay. Nothing in that cap limits any liability that cannot lawfully be limited, including the non-excludable rights you have under the Australian Consumer Law.
Get the tool and the occasional note
The command line auditor will be free and will need no sign-up. Leave an email if you want the release notes and the technical write-ups as they land.
Bring us the database. We’ll bring the proof.
A signed authorisation, a staging clone, and an agreed start date. You get the report and the test that keeps it true.