01 · Access
Share only what is needed
The review is scoped through the Upwork project. Do not send production passwords or service-role keys in chat.
PostgreSQL · Supabase · RLS
“RLS enabled” isn’t “RLS correct.” I review the authorization layer between your PostgreSQL database and your users: Row Level Security policies, exposed objects, multi-tenant boundaries and privileged-key usage. You receive a prioritized report you can act on.
Fixed-price project · platform checkout. No account needed to ask: email cnkkurtoglu@gmail.com with two or three sentences and I will tell you whether an audit is the right thing — including when it is not.
Audit coverage
Reproducible proof
The public fixture uses the same five-test suite to demonstrate a missing database-level RLS boundary and its policy fix. On the current fixed branch, all five isolation checks pass locally with no cloud project, Docker setup or credentials.
Not ready for a $99 audit?
An 8-page PDF covering RLS, secrets, authentication, performance, SEO, reliability and go-live checks. It is an educational review aid—not an automated scan, penetration test or security guarantee.
Confirmed by the teams
“Cenk identified a genuine and significant Supabase RLS issue in CrewForm and disclosed it privately and responsibly. His report was clear, technically accurate, and included practical steps to verify the issue and resolve it. This allowed us to confirm the problem and get a fix in place quickly. He was professional, constructive, and easy to work with throughout the process.”
Separately, an open-source maintainer fixed two vulnerabilities I reported — an anon-reachable SECURITY DEFINER function that bypassed RLS, and a USING (true)policy exposing every signed-in user's email — and credited the report in a public commit, verified against production.
01 · Access
The review is scoped through the Upwork project. Do not send production passwords or service-role keys in chat.
02 · Review
Policies are evaluated against your user roles and data ownership model, not against a generic checklist alone.
03 · Report
Findings are prioritized by impact, with affected objects, reproduction notes and concrete remediation guidance.
Before you order
No. It is a focused review of the Supabase authorization boundary described in the Upwork scope, not a full application penetration test or security guarantee.
Yes. Cross-tenant access is tested against the supplied membership and ownership model, including negative cases between separate synthetic tenants.
No production password or service-role key should be sent in chat. The review begins with the minimum anonymized schema, policies and reproduction material needed for the agreed scope.
Findings are prioritized by impact and include affected objects, reproduction notes, remediation guidance and verification evidence for the reviewed paths.
Review the service scope before ordering.
All contracting and payment stays on Upwork. Questions do not: write to cnkkurtoglu@gmail.com.