I will lovable app production ready edge functions with a supabase security audit rls


About this gig
Your Lovable app looks finished. Then someone opens the network tab, copies your
anon key, and reads every row in your database. No login needed.
That is not a rare bug. It is the default state of most Lovable and Supabase
projects: RLS switched off, policies set to true, service role keys shipped
inside the browser bundle, secrets hiding behind a VITE_ prefix.
I close those holes.
WHAT YOU GET
- Table by table Row Level Security audit with a plain English exposure report
- RLS policies written, tested and deployed
- Service role and API key cleanup, moved server side
- Auth rules, user roles and custom claims that match your product
- Storage bucket policies so uploaded files stop being public
- Edge function and webhook hardening
- A re-test after the fix, with proof of what changed
WHO THIS IS FOR
Founders charging real money, agencies handing over client builds, teams storing
user data, payments, health data or anything private.
WORKING WITH ME
AWS Certified DevOps Engineer (Professional). I work across your business hours
and overnight, so you are never sitting on a blocker until tomorrow.
Send your project link and I will tell you what is exposed before you order.
Get to know Gbenga
Lovable app, Base44 app, Replit app, Supabase Fullstack Engineer Postgresql
- FromNigeria
- Member sinceMay 2026
- Avg. response time1 hour
Languages
English, Spanish, German, Italian, French, Dutch, Portuguese
My Portfolio
FAQ
Do you need access to my Lovable project?
Only your Supabase project (or Lovable Cloud) and read access to the GitHub repo. Most of the work happens in the database, not the editor. I can also work from a temporary collaborator invite that you revoke on delivery.
Will fixing RLS break my app?
It can, and that is the point. Turning RLS on with no policy blocks everything until the right policy exists. I write the policies alongside, test every user flow, and hand back an app that works and blocks strangers.
How do I know if my app is actually exposed?
Send me the live link. I run a read test against your tables using only the public key that already ships in your browser bundle. If rows come back without logging in, you are exposed, and I will show you which tables.
Can you move me off Lovable Cloud to my own Supabase project?
Yes. There is no one-click path for this, so it is a manual migration: schema, data, storage files and auth users into a Supabase project you own and bill. That is part of the Premium package or a paid extra.
My payments stopped working after going live. Related?
Often yes. Stripe webhooks created during the build usually still point at the preview URL, so payments succeed but access never unlocks. I check webhook endpoints, signing secrets and live mode as part of hardening.
Do you write the code or just tell me what to fix?
I write and deploy the SQL, policies and function changes myself on Standard and Premium. Basic is audit only: you get the report and the exact fix list if you would rather hand it to your own developer.
What if I built with Bolt, Replit, Base44 or Cursor instead?
Same work. The security gaps come from how AI builders scaffold Postgres and ship keys to the browser, not from which builder you used. Send the repo and the database and I will scope it.
How fast can you start, and what are your hours?
Usually same day. I work across your business hours and overnight, so a message at any point in your day gets an answer inside a few hours, not the next morning.

