Names that lie
A rule called “Service role can manage…” with no role on it applies to everyone. Reviewers, human or AI, read the name and move on.
create policy "Service role…" using (true)Supabase security reviews for AI-built apps
Rowlock reads every Supabase rule in your repo, finds the ones that let strangers read or change your users’ data, and hands you the exact SQL to fix them.
-- looks server-only create policy "Service role can manage payments" on payments for all using (true);
Critical · no to service_role. Anyone with your public key can read, change and delete every payment.
-- fix: the server's key bypasses RLS anyway drop policy "Service role can manage payments" on payments; create policy "owners read their payments" on payments for select to authenticated using ((select auth.uid()) = user_id);
For apps built with
What we check
The Security Advisor catches obvious always-true rules, and we check those too. These are the four patterns we found it misses or can’t judge, because they depend on what your data is.
A rule called “Service role can manage…” with no role on it applies to everyone. Reviewers, human or AI, read the name and move on.
create policy "Service role…" using (true)“Must be logged in” sounds safe until you remember anyone can sign up. These rules don’t contain true, so a search for true never finds them.
using (auth.uid() is not null)Postgres allows access if any rule says yes. Add a careful rule without dropping the loose one and nothing changes, but the code looks fixed.
loose rule OR strict rule = looseSupabase’s linter skips read rules by design. We judge each table by what it holds: waitlists, messages, subscriptions, profiles.
for select using (true)What you get
No 60-page PDF of scanner output. Each finding says what’s exposed, to whom, and how to close it.
Database Check · acme-app
142 rules on 31 tables reviewed
| # | Severity | Finding | Who | Can |
|---|---|---|---|---|
| F1 | Critical | payments “Service role” rule applies to everyone | Anyone | Read · change · delete |
| F2 | High | messages Old loose rule cancels the participant-only fix | Any signed-in user | Read · send · edit |
| F3 | High | waitlist “Must be logged in” exposes every email | Any signed-in user | Read |
| F4 | Medium | audit_log Insert rule lets anyone forge entries | Anyone | Add |
How it works
Tell us about your app, choose a plan and pay securely through Stripe.
Read-only access or a zip. We never need your database keys or live app.
Every finding ranked by risk, in plain English, with the SQL that fixes it.
Apply the fixes. On the Launch Audit we check again to confirm they’re closed.
Pricing
A one-time audit finds what’s leaking today. Rowlock Watch keeps checking as your app changes. All prices in Canadian dollars (CAD).
One-time payment Audits, priced per app
The full Database Check at a founding price, for our first five clients.
$149per app
3–4 business days
Choose Founding clientIn return, we may publish an anonymised case study. Five places only.
Every Supabase rule in your repo, read in full and judged against what the table holds.
$349per app
2–3 business days
Choose Database CheckThe Database Check plus the rest of what leaks in AI-built apps, and a retest.
$649per app
3–5 business days
Choose Launch AuditSubscription · ongoing
An audit is a snapshot. Your AI builder keeps writing new migrations. Watch checks every new database change before it reaches your users.
Every new Supabase migration in one repo checked before it ships.
$49/ month
Billed monthly · or $490 / year
Subscribe to Watch StarterFor teams shipping often across several apps.
$149/ month
Billed monthly · or $1,490 / year
Subscribe to Watch ProRenews automatically until you cancel. Cancel anytime; you keep access to the end of the period you’ve paid for.
We write the migration, remove the loose rules, and check your app still works. Quoted after your audit.
Ask after your audit, or write to info@itacc.ca
Enterprise
For agencies, studios and companies shipping several AI-built apps. Custom pricing, one contract.
We reply within one business day.
Security
We review security for a living. Here’s how we treat yours.
We work from your code. We never ask for your database password or service role key, and never touch your production app.
Grant read-only repo access or send a zip. Revoke it the moment your report arrives.
Our copy of your code is deleted within 30 days of delivery. Reports stay yours.
We don’t name or describe your app anywhere without your written permission. NDAs on request.
No. It’s a code review of your database rules and configuration, read from your repository. We don’t attack your live app. If you need a full pentest, we’ll tell you and point you to one.
No. We work from the SQL in your repo: migrations and schema files. We never ask for your database password or service role key. If your rules were made in the dashboard instead of in code, we’ll send you one query to run and paste back.
Any app on Supabase, however it was built: Lovable, Bolt, Replit, v0, Cursor, Claude Code, or by hand. Firebase support is on the way.
Then your report says so, lists what we checked, and you have proof of a clean review to show users or investors.
We read it only for your review and delete our copy within 30 days of delivering the report. We never publish anything about your app without your written permission.
Yes. Tick “I need a signed NDA” at checkout and we’ll email our mutual NDA to e-sign right after payment. We start once it’s signed. Enterprise customers can send their own.
Stripe emails a receipt as soon as you pay, and we send an order confirmation with next steps. Need an invoice with your company name or tax ID? Add them at checkout and it comes as a PDF.
Yes, a full refund any time before we start the review. After that, if you’re unhappy with the report, write to us and we’ll make it right. Rowlock Watch: cancel anytime, and get your first payment back if you cancel within 14 days.
Before your users do. Reports in 2–5 business days, from $149.