I will secure your lovable, replit or base44 app supabase database

O
oddlobster
O
oddlobster
Raphael

About this gig

Your Lovable or Bolt app works. That is not the same as being safe.

Supabase ships your project URL and anon key inside the frontend bundle. That is by design and it is only safe if Row Level Security is on and the policies are right. New tables arrive with RLS off and AI builders add tables constantly without switching it on.


So anyone can open devtools, take your key, and query your database directly. Users, orders, messages, all of it readable. Nothing breaks, which is why owners never find out.

I test your app the way an attacker would. I pull your key from the bundle, enumerate every table, and attempt read, insert, update and delete on each one from outside your app entirely. You get a table showing exactly what an anonymous visitor can reach.

Then I close it. Policies written and verified by re-running the same test until every endpoint returns nothing while your app still works normally.

Covered: RLS policies, auth and session handling, service role key exposure, storage bucket permissions, schema and foreign key issues, API and webhook wiring.

Not covered: UI work, design changes, app store submissions.

Send me your app URL before ordering and I will tell you what I find

Get to know Raphael

Raphael
5.0(1)
  • FromAustria
  • Member sinceMay 2022
  • Avg. response time1 hour
  • Last delivery3 years
  • Languages

    English, German
Hello, I'm Raphael, a final-year master's student specializing in Data Science and Machine Learning. With a solid background in programming spanning 5 years, I bring expertise in AI, Data Science, Data Visualization, Data Processing, Data Collection, Web Scraping, and Machine Learning to the table.