I will audit and fix supabase rls and security issues in your vibe coded app


About this gig
Built your app with Lovable, Bolt, Base44, Replit or Cursor? It can look perfect in the browser while anyone can read your database or grab your API keys.
Independent 2026 scans of AI-built apps keep finding the same mistakes: Supabase tables readable without login, and secret keys shipped in frontend code.
I'm a backend-focused full-stack developer (Node.js, TypeScript, PostgreSQL). I review your app the way an attacker would, then fix what's exposed.
WHAT I CHECK
- RLS enabled and correct on every Supabase table
- Secret keys (service_role, Stripe, OpenAI) in frontend code
- Users reading or editing other users' data
- Unprotected API routes and edge functions
- Stripe webhook signature verification
- Public storage buckets
WHAT YOU GET
- Plain-English findings report, critical to low
- Fixes applied (Standard and Premium)
- Re-check to confirm every fix holds
This is a manual code and configuration review, not a certified pentest.
Send me your app link first for a quick look before you order.
Get to know Samin Ravi
Full Stack TypeScript Developer, I Fix and Ship AI Built Apps
- FromBangladesh
- Member sinceJul 2026
Languages
Bengali, English, Urdu, Hindi
My Portfolio
Other Vibe Coding Services I Offer
FAQ
Is this a penetration test or compliance certification?
No. It is a manual code and configuration security review focused on the flaws AI coding tools commonly create. It is not a certified pentest or a compliance audit (SOC 2, HIPAA).
Do you need my passwords?
No. Read access to your GitHub repo and a collaborator invite to your Supabase project are enough.
Will my vulnerabilities be shared?
Never. Findings stay private between us, and I do not publish or reuse your details.
Can you fix the issues too?
Yes. Standard fixes all critical and high findings. Premium fixes everything found, then re-checks.
Which package do I need?
Basic if you want to know where you stand. Standard if you want critical issues fixed. Premium before launching to real users or taking payments.

