I will audit your supabase rls and fix multi tenant data leaks

Brazil

I speak Portuguese, English

Full Stack Developer, Data Security and Excel Automation

Full-stack developer and solo creator of two live products: ShipSealed (open-source RLS tools + SaaS boilerplate for Supabase, with automated tenant-isolation tests) and Zingui (personal finance app w...
About this Gig

Is your Supabase database actually safe, or is one user a query away from reading another user's data?


Row Level Security (RLS) is what keeps your users' data isolated. When it is misconfigured (a policy set to FOR ALL, a missing WITH CHECK, an anon key with too much reach), any user can read or edit data that is not theirs, and you will not see it until it is a breach.


I build security tooling for Supabase. I am the creator of Airlock (an open-source RLS toolkit on npm) and ShipSealed, a SaaS boilerplate whose tenant isolation is proven by automated tests. I audit RLS the way an attacker would probe it, then close the gap and prove it is closed.


WHAT YOU GET

A clear report of every RLS and auth hole, ranked P0, P1, P2. Exactly which policy is wrong and why it leaks. On Premium, the fix plus automated tests proving one user cannot touch another user's rows.


WHY ME

Real shipped products, not just theory. I prove isolation with tests, I do not just claim it. Plain, honest reporting.


Not sure which package fits? Message me about your project and I will point you to the right one before you order.

Tools:

GitHub

Supabase

Frameworks:

Npm

Cloud Provider:

Amazon Web Services

Programming language:

JavaScript

Expertise:

Debugging

Development

Configuration

My Portfolio