I will secure your supabase backend with tested rls policies and auth rules

S
sahan411
S
sahan411
Sahan K

About this gig

Launching an app on Supabase (built with Lovable, Bolt, Replit, Cursor or by hand)? Wrong or missing Row Level Security is the most common way these apps leak user data. I make your backend safe to launch, and prove it.


I work from your schema alone: send the supabase/migrations folder or a schema dump (exact steps come with the order). I never need your keys, passwords or live access.


What makes this different: I don't only read policies, I run them. Your schema is loaded into a real Postgres sandbox and tested as a logged-out visitor and as User A trying to read, change, delete or forge User B's rows. You get proof of what the database actually allows, before and after the fix.


You receive:

  • Findings ranked critical to low, in plain English
  • Exact SQL: RLS policies, auth rules, storage policies
  • Access-test results before and after (Secure it and up)


Checks: RLS off, always-true policies, policies trusting user_metadata, views exposing auth.users, risky SECURITY DEFINER functions, storage policies.


Honest limits: schema-level work, not a penetration test. I use AI-assisted tooling plus my own open-source audit tool, and every fix is re-tested before delivery.

Get to know Sahan K

Sahan K

Computer Engineering UG IOT Embedded Systems Engineering

  • FromSri Lanka
  • Member sinceDec 2020
  • Languages

    English
I am a Computer Engineering student at the University of Ruhuna with a focus on IoT, Embedded Systems Engineering, and AI automation. I have professional experience as a Co-Founder at SolutionEngine and as an Embedded Software Engineer Trainee, specializing in multithreading and prompt engineering.