I will audit your supabase rls policies and test data isolation


About this gig
Your app works. But can user A read user B's data by calling the API directly? On apps built with Lovable, Bolt or plain Supabase, that's the most common and most invisible flaw.
WHAT I DO
- Review every RLS policy, table by table (select / insert / update / delete)
- Check security-definer functions, helper grants, service-role usage
- Scan the repo and Git history for leaked secrets
- Test isolation with fictitious accounts on a test project: owner, read-only guest, stranger, anonymous, revoked, expired
- Verify each refusal by row count, not just "no error"
WHAT YOU GET
- A written report ranked critical / high / medium / low, with file, line, risk and fix
- Standard+: a rerunnable automated test suite you keep
- Premium: fixes as pull requests, one per finding, nothing merged without your OK
HOW I WORK
Read-only unless you order fixes. No real user data ever needed. Fixed scope, fixed price, written exclusions. Replies within 24 h.
Background: I run a production health-data app with end-to-end encryption, WAF and tested backups, and built a 54-scenario RLS test suite for a care-coordination app.
Not sure which package fits? Message me with your table count.
Get to know Yan
Supabase RLS App Security Auditor Web Developer
- FromFrance
- Member sinceSep 2026
Languages
French, English

