NewOur study: half the AI-built apps we could inspect let the wrong person write to their data.
Rowlock

Supabase security reviews for AI-built apps

Your database rule says “server only”. It means everyone.

Rowlock reads every Supabase rule in your repo, finds the ones that let strangers read or change your users’ data, and hands you the exact SQL to fix them.

  • No database keys needed
  • Report in 2–5 business days
  • Exact SQL fixes included
migrations/20250706_payments.sql
-- looks server-only
create policy "Service role can manage payments"
  on payments for all
  using (true);

Critical · no to service_role. Anyone with your public key can read, change and delete every payment.

-- fix: the server's key bypasses RLS anyway
drop policy "Service role can manage payments" on payments;
create policy "owners read their payments" on payments
  for select to authenticated
  using ((select auth.uid()) = user_id);
Every finding ships with the SQL that fixes it. Example simplified.

For apps built with

  • Lovable
  • Bolt
  • Replit
  • v0
  • Cursor
  • Claude Code

From our study of public AI-built apps · September 2026

Read the report
1,176
live database rules read by hand across 21 AI-built apps
10 of 21
apps had a rule letting the wrong person write to their data
6
apps let strangers or any signed-up user read personal data
3
of our four checks catch problems Supabase’s linter doesn’t flag

What we check

What Supabase’s Advisor doesn’t tell you

The Security Advisor catches obvious always-true rules, and we check those too. These are the four patterns we found it misses or can’t judge, because they depend on what your data is.

Names that lie

A rule called “Service role can manage…” with no role on it applies to everyone. Reviewers, human or AI, read the name and move on.

create policy "Service role…" using (true)

Rules that only look strict

“Must be logged in” sounds safe until you remember anyone can sign up. These rules don’t contain true, so a search for true never finds them.

using (auth.uid() is not null)

Fixes that don’t work

Postgres allows access if any rule says yes. Add a careful rule without dropping the loose one and nothing changes, but the code looks fixed.

loose rule OR strict rule = loose

Private data open to read

Supabase’s linter skips read rules by design. We judge each table by what it holds: waitlists, messages, subscriptions, profiles.

for select using (true)

What you get

A report your team can act on the same day

No 60-page PDF of scanner output. Each finding says what’s exposed, to whom, and how to close it.

  • Every rule on every table, read in full
  • Findings ranked by risk, in plain English
  • Who can do what, before and after the fix
  • The exact SQL migration for each fix
  • A walkthrough call with your reviewer

Database Check · acme-app

142 rules on 31 tables reviewed

1 critical2 high1 medium
#SeverityFindingWhoCan
F1Criticalpayments

“Service role” rule applies to everyone

AnyoneRead · change · delete
F2Highmessages

Old loose rule cancels the participant-only fix

Any signed-in userRead · send · edit
F3Highwaitlist

“Must be logged in” exposes every email

Any signed-in userRead
F4Mediumaudit_log

Insert rule lets anyone forge entries

AnyoneAdd
Sample report. Names changed; each finding includes its fix migration.

How it works

From order to fixed in under a week

  1. Step 1

    Order online

    Tell us about your app, choose a plan and pay securely through Stripe.

  2. Step 2

    Share your repo

    Read-only access or a zip. We never need your database keys or live app.

  3. Step 3

    Get your report

    Every finding ranked by risk, in plain English, with the SQL that fixes it.

  4. Step 4

    Fix and retest

    Apply the fixes. On the Launch Audit we check again to confirm they’re closed.

Pricing

Pay once for an audit, or stay covered

A one-time audit finds what’s leaking today. Rowlock Watch keeps checking as your app changes. All prices in Canadian dollars (CAD).

One-time payment Audits, priced per app

Founding client

The full Database Check at a founding price, for our first five clients.

$149per app

3–4 business days

Choose Founding client
  • Everything in Database Check
  • Direct line to the reviewer
  • Your feedback shapes the product

In return, we may publish an anonymised case study. Five places only.

Database Check

Every Supabase rule in your repo, read in full and judged against what the table holds.

$349per app

2–3 business days

Choose Database Check
  • Every policy on every table reviewed
  • The problems Supabase's Advisor doesn't flag
  • Report in plain English, ranked by risk
  • Exact SQL to fix each finding
  • 30-minute walkthrough call
Most complete

Launch Audit

The Database Check plus the rest of what leaks in AI-built apps, and a retest.

$649per app

3–5 business days

Choose Launch Audit
  • Everything in Database Check
  • Leaked keys and secrets in frontend code
  • Storage buckets and edge functions
  • Auth settings (sign-ups, anonymous users)
  • One retest after you fix

Subscription · ongoing

Rowlock Watch

An audit is a snapshot. Your AI builder keeps writing new migrations. Watch checks every new database change before it reaches your users.

Watch Starter

Every new Supabase migration in one repo checked before it ships.

$49/ month

Billed monthly · or $490 / year

Subscribe to Watch Starter
  • 1 repository
  • Every new migration and policy change reviewed
  • Alert with the exact SQL fix when a rule leaks
  • Monthly summary of your database rules
  • Cancel anytime

Watch Pro

For teams shipping often across several apps.

$149/ month

Billed monthly · or $1,490 / year

Subscribe to Watch Pro
  • Up to 5 repositories
  • Same-business-day checks
  • Storage buckets and edge functions included
  • Quarterly 30-minute review call
  • Priority support · cancel anytime

Renews automatically until you cancel. Cancel anytime; you keep access to the end of the period you’ve paid for.

Fix it for you · from $300

We write the migration, remove the loose rules, and check your app still works. Quoted after your audit.

Ask after your audit, or write to info@itacc.ca

Enterprise

Reviewing more than one app?

For agencies, studios and companies shipping several AI-built apps. Custom pricing, one contract.

  • Reviews across all your apps and repos
  • NDA and your security questionnaire
  • Invoicing and purchase orders
  • Priority turnaround and a named reviewer
  • Team walkthrough and remediation support

Talk to sales

We reply within one business day.

Security

How we handle your code

We review security for a living. Here’s how we treat yours.

No keys, no live access

We work from your code. We never ask for your database password or service role key, and never touch your production app.

Read-only by design

Grant read-only repo access or send a zip. Revoke it the moment your report arrives.

Deleted in 30 days

Our copy of your code is deleted within 30 days of delivery. Reports stay yours.

Never published

We don’t name or describe your app anywhere without your written permission. NDAs on request.

Questions

Is this a penetration test?

No. It’s a code review of your database rules and configuration, read from your repository. We don’t attack your live app. If you need a full pentest, we’ll tell you and point you to one.

Do you need access to my Supabase project or live app?

No. We work from the SQL in your repo: migrations and schema files. We never ask for your database password or service role key. If your rules were made in the dashboard instead of in code, we’ll send you one query to run and paste back.

Which tools do you support?

Any app on Supabase, however it was built: Lovable, Bolt, Replit, v0, Cursor, Claude Code, or by hand. Firebase support is on the way.

What if you don’t find anything?

Then your report says so, lists what we checked, and you have proof of a clean review to show users or investors.

What happens to my code?

We read it only for your review and delete our copy within 30 days of delivering the report. We never publish anything about your app without your written permission.

Can you sign an NDA?

Yes. Tick “I need a signed NDA” at checkout and we’ll email our mutual NDA to e-sign right after payment. We start once it’s signed. Enterprise customers can send their own.

Do I get a receipt or invoice?

Stripe emails a receipt as soon as you pay, and we send an order confirmation with next steps. Need an invoice with your company name or tax ID? Add them at checkout and it comes as a PDF.

Can I get a refund?

Yes, a full refund any time before we start the review. After that, if you’re unhappy with the report, write to us and we’ll make it right. Rowlock Watch: cancel anytime, and get your first payment back if you cancel within 14 days.

Find out what your rules really allow.

Before your users do. Reports in 2–5 business days, from $149.