I will audit your lovable bolt supabase app for rls and security


About this gig
Your AI-built app works. But is it actually safe to launch?
This is a technical security review not a penetration test or compliance audit. I check what your Supabase setup actually allows, not what your AI tool claims is configured.
I only need read-only access a collaborator invite or your schema/migrations. I never ask for your service-role key, and any live checks are rollback-safe.
I specialize in auditing apps built with Lovable, Bolt, Replit, Cursor and Base44 on Supabase/PostgreSQL focused on Row Level Security (RLS), authentication, authorization and data exposure.
What I check: RLS policies, table-level access, anonymous access, auth & roles, SECURITY DEFINER functions, exposed keys/credentials, storage policies, Edge Functions, data isolation.
You'll receive a prioritized report Critical / High / Medium / Recommendation explaining what's wrong, why it matters, and how to fix it. No jargon, no generic scan dump.
Want it fixed too? Choose Premium and I'll implement and retest critical fixes.
Unsure which package fits? Message me your stack first.
Get to know Nicolas M.
Technology Product Engineering Leader
- FromUnited Kingdom
- Member sinceFeb 2024
- Avg. response time1 hour
Languages
English, Spanish
My Portfolio
FAQ
Can you audit an application built with Lovable or Bolt?
Yes — that's my specialty, particularly when it's on Supabase.
Do you check Supabase RLS?
Yes, RLS is the core of the audit — policies, table access, roles, and whether users can reach other users' data.
Do you only run an automated security scanner?
No. Automated tools can miss application-specific authorization problems or produce false positives. I manually review the configuration and verify actual behavior where appropriate.
Do you need my service-role key or full admin access?
No. A read-only invite to your Supabase project, or just your schema and migration files, is enough for Basic and Standard. Premium (where I implement fixes) needs write access to a staging or branch copy only — never production directly.
What if you don't find any security problems?
That's a good result — you'll still get a report documenting what was reviewed and confirming the security status.
Can you fix the issues you find?
Yes, on Premium — I implement and retest critical/high-priority fixes.
Is this a penetration test?
No. This is a technical application security and configuration audit, not a formal pentest, certification or compliance audit.
What access do you need?
Depends on scope — I'll confirm exactly what's needed after reviewing your project.

