Ik audit je supabase rls policies en test dataseparatie

B
bele_tech
B
bele_tech
Yan
Sommige informatie is automatisch vertaald.

Over deze dienst

Automatische vertaling

Je app werkt. Maar kan gebruiker A de data van gebruiker B lezen door de API direct aan te roepen? Bij apps gebouwd met Lovable, Bolt of plain Supabase is dat de meest voorkomende en meest onzichtbare fout.


WAT IK DOE

- Elke RLS policy bekijken, tabel voor tabel (select / insert / update / delete)

- Controleer security-definer functies, helper grants, service-role gebruik

- Scan de repo en Git geschiedenis op gelekte secrets

- Test isolatie met fictieve accounts op een testproject: eigenaar, read-only gast, vreemdeling, anoniem, ingetrokken, verlopen

- Verifieer elke weigering op rijtelling, niet alleen "geen fout"


WAT JE KRIJGT

- Een schriftelijk rapport met ranking kritisch / hoog / medium / laag, met bestand, regel, risico en oplossing

- Standard+: een herhaalbare geautomatiseerde test suite die je behoudt

- Premium: fixes als pull requests, één per bevinding, niets gemerged zonder jouw goedkeuring


HOE IK WERK

Alleen-lezen tenzij je fixes bestelt. Geen echte gebruikersdata nodig. Vastgestelde scope, vaste prijs, schriftelijke uitsluitingen. Reacties binnen 24 uur.


Achtergrond: Ik beheer een productie health-data app met end-to-end encryptie, WAF en geteste backups, en heb een RLS test suite van 54 scenario's gebouwd voor een zorgcoördinatie app.


Weet je niet welke package past? Stuur me een bericht met je aantal tabellen.


Maak kennis met Yan

Yan

Supabase RLS App Security Auditor Web Developer

  • Afkomstig uitFrankrijk
  • Lid sindssep 2026
  • Talen

    Frans, Engels
I audit and fix the security of web apps built fast (Lovable, Bolt, Supabase, Next.js). Specialty: Row Level Security and data isolation. I test whether user A can really read or edit user B's data by calling the API directly, and hand you a reproducible test suite you keep. Cybersecurity & networks background; I run a production health-data app with end-to-end encryption, WAF and tested backups. You get a written report (critical to low, file, line, fix). No changes without your OK, no real user data needed. Fixed prices, written scope.

Automatische vertaling