Is this a penetration test?
No. It is a focused review of the Supabase authorization boundary described in the Upwork scope, not a full application penetration test or security guarantee.
Supabase · RLS · Next.js
I review the authorization layer between your Supabase database and your users: RLS policies, exposed objects, tenant boundaries and privileged-key usage. You receive a prioritized report you can act on.
Audit coverage
Reproducible proof
The public fixture uses the same five-test suite to demonstrate a missing database-level RLS boundary and its policy fix. On the current fixed branch, all five isolation checks pass locally with no cloud project, Docker setup or credentials.
Not ready for a $299 audit?
An 8-page PDF covering RLS, secrets, authentication, performance, SEO, reliability and go-live checks. It is an educational review aid—not an automated scan, penetration test or security guarantee.
01 · Access
The review is scoped through the Upwork project. Do not send production passwords or service-role keys in chat.
02 · Review
Policies are evaluated against your user roles and data ownership model, not against a generic checklist alone.
03 · Report
Findings are prioritized by impact, with affected objects, reproduction notes and concrete remediation guidance.
Before you order
No. It is a focused review of the Supabase authorization boundary described in the Upwork scope, not a full application penetration test or security guarantee.
Yes. Cross-tenant access is tested against the supplied membership and ownership model, including negative cases between separate synthetic tenants.
No production password or service-role key should be sent in chat. The review begins with the minimum anonymized schema, policies and reproduction material needed for the agreed scope.
Findings are prioritized by impact and include affected objects, reproduction notes, remediation guidance and verification evidence for the reviewed paths.
Review the service scope before ordering.
All contracting and payment stays on Upwork.