Sixthgear

Supabase Leak Check for Lovable & Bolt apps

A fast, read-only security check for apps built on Supabase — the kind of misconfiguration that ships quietly with AI-generated backends and stays invisible until someone finds it first.

How it works

What I check

Row Level Security policies, table grants, storage bucket permissions, and keys that shouldn't be public — the exact places Lovable/Bolt-generated backends tend to leave open.

How

Entirely read-only: your public anon key plus a policy review, the same way any visitor to your app could look. No data is copied or stored — I check whether a request succeeds, not what comes back.

What you get

A written report within 48 hours: plain-English findings, exactly who can exploit each one, and the exact SQL to fix it — not a vague score.

Sample report

LeadBox — Supabase Data Leak Check

A real audit against a demo Supabase project: what was exposed, the proof, the fix, and the same checks re-run clean afterwards.

Download the sample (PDF)

Pricing

$390
Fix pack — I apply the SQL fixes and re-verify
$49/mo
Monthly re-check — catches new tables and policy drift

Payment by invoice, bank transfer — EU, US, and UK clients.

Built on open tools

The audit runs on two open-source tools I maintain — read the source, don't just take my word for it.