Use case · Vibe-coders

Supabase security audit.

Supabase is safe when row-level security is right, and wide open when it isn't. Deeraf checks every table, bucket and function so you know which one you have.

Sounds familiar?

  1. 01RLS is off on some tables, or you're not sure
  2. 02Policies that just say true
  3. 03The service role key appears in client code
  4. 04Public storage buckets holding user files
  5. 05Edge functions that trust whatever the client sends

How Deeraf handles it.

  1. 01

    Map

    Every table, policy, bucket, function and key, and which role can reach each one.

  2. 02

    Probe

    Requests made as an anonymous and a signed-in user to prove what leaks, not guess.

  3. 03

    Lock down

    Corrected policies and a fix plan, or the fixes themselves in a Sprint.

The result

Every table answers only to the users who should see it.

Start a Tech Check
Start with3–5 days

Tech Check

Full audit and a prioritized fix list.

From $800

Questions.

Do you need access to my production database?

Read access to the project settings and schema is enough for the audit. Fixes are tested on a branch or staging project before they reach production.

Is the anon key a secret?

No, it's designed to be public. What protects your data is row-level security. The service role key is the one that must never reach the browser.

Do you also review Firebase?

Yes. Firestore security rules have the same failure modes and get the same treatment.

Further reading