I will audit and fix supabase rls and security issues in your vibe coded app

S
saminravi99
S
saminravi99
Samin Ravi

About this gig

Built your app with Lovable, Bolt, Base44, Replit or Cursor? It can look perfect in the browser while anyone can read your database or grab your API keys.


Independent 2026 scans of AI-built apps keep finding the same mistakes: Supabase tables readable without login, and secret keys shipped in frontend code.


I'm a backend-focused full-stack developer (Node.js, TypeScript, PostgreSQL). I review your app the way an attacker would, then fix what's exposed.


WHAT I CHECK

  • RLS enabled and correct on every Supabase table
  • Secret keys (service_role, Stripe, OpenAI) in frontend code
  • Users reading or editing other users' data
  • Unprotected API routes and edge functions
  • Stripe webhook signature verification
  • Public storage buckets


WHAT YOU GET

  • Plain-English findings report, critical to low
  • Fixes applied (Standard and Premium)
  • Re-check to confirm every fix holds


This is a manual code and configuration review, not a certified pentest.


Send me your app link first for a quick look before you order.

Get to know Samin Ravi

Samin Ravi

Full Stack TypeScript Developer, I Fix and Ship AI Built Apps

  • FromBangladesh
  • Member sinceJul 2026
  • Languages

    Bengali, English, Urdu, Hindi
I help founders turn AI built apps into reliable products. If your Lovable, Bolt, Base44 or Replit app broke after launch, whether it is login loops, Supabase errors, Stripe not unlocking access or failed deploys, I find the root cause and fix it properly. I am a full stack TypeScript developer with over 4 years of experience building production systems with Node.js, Next.js, PostgreSQL, Supabase, Stripe, Docker and AWS. I have shipped AI SaaS products and published an open source npm package. Send me your project link and I will tell you honestly what is wrong before you order.

My Portfolio

Other Vibe Coding Services I Offer