Understand
After purchase, we confirm the agreed scope, your user and tenant model, and the questions to answer. NDA and restricted access arrangements come before the review.
Supabase Security Audit & AI Code Review
AI-built and vibe-coded apps often move quickly on Supabase. I independently review RLS policies, tenant isolation, Auth, Storage, Edge Functions and privileged-key handling, then recommend what your team should address before real customer data depends on those boundaries.
Business customers only. Read-only advisory audit; report and recommendations, no implementation.
01 / The assessment
This Supabase security and AI code review examines whether grants, RLS policies and application access paths match your intended permissions. I review the available evidence for user and tenant isolation, privileged operations and file access, then separate material risks from checks your team still needs to perform.
You receive
A prioritized view of authorization and data-access risks with affected objects, business impact, and concrete remediation guidance.
02 / How it works
After purchase, we confirm the agreed scope, your user and tenant model, and the questions to answer. NDA and restricted access arrangements come before the review.
I review the agreed code, configuration and existing evidence using read-only access or sanitized exports.
You get a direct report ordered by technical risk, business impact and remediation value.
We walk through the findings and recommended actions. Your team decides, tests and implements any changes.
“RLS enabled is not the same as RLS correct.”
A pragmatic approach
A policy can exist and still be wrong for your product. I review your intended ownership model, shared records, roles and privileged access paths, then prioritise the gaps that could expose another user's or tenant's data.
Egidijus GirčysAbout me
I’m based in Berlin, Germany and work with startups and product teams internationally. I’ve been building production software professionally since 2013, helping organizations move from early decisions to reliable systems, migrations, and healthier engineering processes.
I use AI extensively in my own work. The goal is not to slow down AI-assisted development. It is to add the architecture, verification and operational discipline that lets you keep moving quickly without losing control.
Common questions
The agreed Supabase security audit scope may include RLS policies, grants, tenant boundaries, Auth, Storage, Edge Functions and application access paths. The key review covers legacy anon and service_role keys and newer publishable and secret keys, where used. You receive evidence, limitations and recommendations. This is a read-only advisory review, not implementation.
I review policies, access paths and existing test evidence against your intended user and tenant model. The standard audit does not create or alter records or run active exploitation tests. Where direct runtime verification is unavailable, the report states that limitation and recommends checks for your team.
No. It is a scoped, point-in-time advisory review, not a formal penetration test or compliance certification. It does not guarantee that every vulnerability is found, and does not include remediation or production changes.
Ready when you are
Understand the authorization risks identified in scope and receive recommended actions for your team. No application changes are included.
Purchase auditFor business customers only. The agreed audit is advisory and read-only. Scope and terms