LeadBox — Supabase Data Leak Check
A real audit against a demo Supabase project: what was exposed, the proof, the fix, and the same checks re-run clean afterwards.
A fast, read-only security check for apps built on Supabase — the kind of misconfiguration that ships quietly with AI-generated backends and stays invisible until someone finds it first.
Row Level Security policies, table grants, storage bucket permissions, and keys that shouldn't be public — the exact places Lovable/Bolt-generated backends tend to leave open.
Entirely read-only: your public anon key plus a policy review, the same way any visitor to your app could look. No data is copied or stored — I check whether a request succeeds, not what comes back.
A written report within 48 hours: plain-English findings, exactly who can exploit each one, and the exact SQL to fix it — not a vague score.
LeadBox — Supabase Data Leak Check
A real audit against a demo Supabase project: what was exposed, the proof, the fix, and the same checks re-run clean afterwards.
Payment by invoice, bank transfer — EU, US, and UK clients.