Sounds familiar?
- 01RLS is off on some tables, or you're not sure
- 02Policies that just say true
- 03The service role key appears in client code
- 04Public storage buckets holding user files
- 05Edge functions that trust whatever the client sends
How Deeraf handles it.
- 01
Map
Every table, policy, bucket, function and key, and which role can reach each one.
- 02
Probe
Requests made as an anonymous and a signed-in user to prove what leaks, not guess.
- 03
Lock down
Corrected policies and a fix plan, or the fixes themselves in a Sprint.
Tech Check
Full audit and a prioritized fix list.
Questions.
Do you need access to my production database?
Read access to the project settings and schema is enough for the audit. Fixes are tested on a branch or staging project before they reach production.
Is the anon key a secret?
No, it's designed to be public. What protects your data is row-level security. The service role key is the one that must never reach the browser.
Do you also review Firebase?
Yes. Firestore security rules have the same failure modes and get the same treatment.