Professional Security Audit

Your Supabase is probably leaking data

I'll find out what's exposed before someone else does. $300, full report, fix recommendations included.

Get Your Audit

The Problem

Most Supabase apps ship with broken RLS, exposed service keys, or auth configs that let users access data they shouldn't.

I've seen it in over 60 companies—including YC startups that thought they were secure.

Common finding:

SELECT * FROM users — returns every user in the database because RLS is disabled or policies are misconfigured.

What You Get

For $300, I'll test your Supabase setup and send you a detailed report covering:

  • Row Level Security policies

    The #1 problem area — I'll check every table and policy

  • Auth and session handling

    JWT validation, session management, auth flows

  • API and key exposure

    Service keys in client code, exposed endpoints

  • Storage bucket permissions

    Public vs private access, upload restrictions

  • Edge function security

    Input validation, auth checks, secret handling

You'll get severity ratings for each finding and clear recommendations on how to fix them.

Once you've made the fixes, I'll verify them for free—just hit me up within 30 days.

Who Am I

M

I'm Minny, CWES certified and the person behind MinnySec.

I've helped 60+ companies lock down their Supabase instances and responsibly disclosed vulnerabilities to startups who had no idea they were exposed.

I put out free Supabase security content on YouTube—but if you want someone to actually test your app, that's what this is for.

Ready to find out?

Fill out the form below and I'll get back to you within 24 hours.

$300 flat rate • Full report in 3-5 days • Free retest included