01 · Inspect
Map every reachable path
Review RLS coverage, policy commands, grants, views, security-definer functions, Storage, Realtime and sensitive columns.
Supabase · PostgreSQL · Digital download
A structured toolkit for finding cross-user and cross-tenant access gaps in Supabase projects: seven SQL audits, 60 checks, a two-user staging runner and reporting templates you can reuse.

Inside the ZIP
Start with the 15-minute path, complete the full eight-pass review, then record every failure and untested path instead of turning missing evidence into a false pass.
01 · Inspect
Review RLS coverage, policy commands, grants, views, security-definer functions, Storage, Realtime and sensitive columns.
02 · Verify
Sign in as two ordinary users from different tenants and test reads, writes, ownership reassignment and anonymous access.
03 · Report
Turn findings into a client-ready report and remediation plan, then repeat the full audit after changes.
Before you buy
Files 01-06 use read-only catalog queries. File 07 wraps its role-simulation probes in BEGIN and ROLLBACK. The optional Node.js harness can perform real API writes, so it is explicitly for staging or another approved test environment.
No. It uses the public project key and two ordinary test-user accounts. A service-role key bypasses RLS and would make the isolation test meaningless.
Yes. The included single-team commercial license permits completed reports and remediation plans for direct clients. Reselling or redistributing the kit itself is not permitted.
No. It is diagnostic and verification tooling. Results require human review and do not certify that an application is secure or compliant.
Prefer a human review?
See the fixed-scope Supabase RLS security audit from $299 on Upwork.