I will audit your lovable supabase rls security and fix what is actually broken


About this gig
Your app works. That is not the same as being safe to charge money on. I shipped a production SaaS on Lovable with Stripe subscriptions, row-level security and two AI providers in the chain. Building it I found a SECURITY DEFINER function carrying Postgres's default PUBLIC grant. A real privilege escalation the build tool's own summary said had not happened. I found it because I stopped believing the summary and ran has_function_privilege against the live database. That is this gig. Not a scan. Evidence. WHAT YOU GET - Every RLS policy listed, with the role it is scoped to and who can really read and write each table - Every SECURITY DEFINER function with has_function_privilege output for anon and authenticated, shown not claimed - An anonymous-role read test across every customer table - A verdict on each scanner finding: real, false positive or deliberate. This is what stops you clicking fix all and taking your own app dark - The exact SQL to fix what is broken (Standard and Premium) HOW IT WORKS Read-only access, or paste your schema and policies. No calls, no meetings, everything in writing. NOT a penetration test, certification or legal advice. If you need those I will say so
Get to know Edgars L
Supabase and Lovable security audits
- FromEstonia
- Member sinceJul 2026
Languages
English, Latvian, Russian, French
My Portfolio
FAQ
Do you need production database access?
No. Read-only project access or a pasted schema and policy list is enough. I never need your production data.
Will you change anything in my app?
Not unless you buy Standard or Premium, and even then you run the migrations yourself. I write them, you apply them, so you stay in control.
My scanner shows warnings. Are they all real?
Usually not. Telling them apart is most of the value here. One of the findings on my own app is deliberate, and fixing it would break authentication.
Do you work with Bubble, Bolt, v0 or Base44?
The RLS and Supabase parts, yes. The platform-specific parts are written for Lovable.
What if you find nothing?
You get the report saying so, with the evidence. That is a useful thing to own, and I would rather deliver it than invent a problem.
What is not covered by this audit?
It is a point-in-time review of the code and configuration you give me access to, with a written verdict on every finding. It is not a certification, a warranty, or a guarantee against future compromise. Changes made after delivery are outside the scope.
Can I check some of this myself first?
Yes, and you should. I put 22 of these checks on a free page with the SQL for each one: lovable-security-check.netlify.app - no signup, nothing stored. If it all passes, you do not need me. Most people finish with a few marked "not sure". That is what I am for.
Is this a real problem, or are you selling fear?
Judge it from the platforms, not from me. Lovable's own April 2026 incident report admits source code on public projects became accessible to any user. Supabase now enables row-level security by default and ships a linter for it. Vendors do not change defaults over rare problems.

