I will run a security audit and fix your lovable or supabase app


About this gig
On 25 September 2026, security researchers at UpGuard reported 16,326 Supabase databases with tables anyone on the internet could read: personal data, and in some cases passwords and tokens.
The usual cause: the AI tool created the tables but row level security (RLS) was never switched on, or the secret key ended up in the browser code.
This security audit is built for vibe coded apps made with Lovable, Bolt, Cursor or Claude Code on Supabase. I find what is exposed, and fix it.
WHAT I CHECK
- Every table: can a stranger read or change it with your public key?
- Row level security policies: missing, too open, or wrong
- Service role or secret keys exposed in frontend code
- Storage buckets open to the public
- Auth: can one user see another user's data?
WHAT YOU GET
- A plain-English vulnerability report: what is exposed, how serious it is, how to fix it
- In Scan + Fix and Full Hardening, the fixes applied and tested
- A before and after test, so you can see it is closed
I only test apps you own, with your permission.
WHO YOU ARE HIRING
I run Purffle, a small studio in Chennai. We build and run our own live web apps and debug AI-written code every day.
Get to know Chaman Raj
Full Stack Developer: I fix and launch Lovable, Base44 and Bolt apps
- FromIndia
- Member sinceMay 2025
- Avg. response time1 hour
Languages
English, Tamil, Telugu
My Portfolio
Other Vibe Coding Services I Offer
FAQ
Will you break my live app?
No. Every fix is tested first, and policies are applied one table at a time.
Do you need my service role key?
No. A project invite is enough. Never paste secret keys in chat.
Is the public (anon) key a problem?
Not by itself. It is meant to be public. The danger is tables without row level security behind it. That is what I check.
What is row level security (RLS)?
A Supabase setting that decides which rows each user can read or change. Without it, anyone with your public key can read the table.

