I will audit your supabase rls policies and test data isolation

B
bele_tech
B
bele_tech
Yan

About this gig

Your app works. But can user A read user B's data by calling the API directly? On apps built with Lovable, Bolt or plain Supabase, that's the most common and most invisible flaw.


WHAT I DO

- Review every RLS policy, table by table (select / insert / update / delete)

- Check security-definer functions, helper grants, service-role usage

- Scan the repo and Git history for leaked secrets

- Test isolation with fictitious accounts on a test project: owner, read-only guest, stranger, anonymous, revoked, expired

- Verify each refusal by row count, not just "no error"


WHAT YOU GET

- A written report ranked critical / high / medium / low, with file, line, risk and fix

- Standard+: a rerunnable automated test suite you keep

- Premium: fixes as pull requests, one per finding, nothing merged without your OK


HOW I WORK

Read-only unless you order fixes. No real user data ever needed. Fixed scope, fixed price, written exclusions. Replies within 24 h.


Background: I run a production health-data app with end-to-end encryption, WAF and tested backups, and built a 54-scenario RLS test suite for a care-coordination app.


Not sure which package fits? Message me with your table count.


Get to know Yan

Yan

Supabase RLS App Security Auditor Web Developer

  • FromFrance
  • Member sinceSep 2026
  • Languages

    French, English
I audit and fix the security of web apps built fast (Lovable, Bolt, Supabase, Next.js). Specialty: Row Level Security and data isolation. I test whether user A can really read or edit user B's data by calling the API directly, and hand you a reproducible test suite you keep. Cybersecurity & networks background; I run a production health-data app with end-to-end encryption, WAF and tested backups. You get a written report (critical to low, file, line, fix). No changes without your OK, no real user data needed. Fixed prices, written scope.