I will secure your supabase database with row level security and auth


Over deze dienst
Supabase is safe by default only if someone configured it. In apps generated by Lovable, Bolt, Replit or Cursor, usually nobody did. Row level security is off, every table is readable with the anon key, the service role key sits in the client bundle, and the app works perfectly right up to the moment one curious user opens the network tab.
I close that hole. I'm a full-stack engineer working daily with PostgreSQL and Supabase. Before software I spent 13 years in industrial automation, where a failing system costs real money.
AUDIT: I review every table, policy, bucket and key, and send a written report of what is exposed, ranked by severity. No changes to your project.
SECURED: row level security enabled and written per table, policies tested against real roles, auth rules corrected, keys moved out of the client and rotated.
HARDENED: everything above plus storage bucket policies, edge function protection, audit logging, and a written document describing every rule so the next developer does not undo it.
Scope: revisions are limited per package. New features and redesign are not included.
Send me your project link before ordering and I'll tell you what I can see from outside.
Maak kennis met Marco Contin
Full Stack Engineer production ready web apps
- Afkomstig uitItalië
- Lid sindsjan 2026
Talen
Italiaans, Engels
Mijn portfolio
Andere Vibe coding diensten die ik aanbied
Veelgestelde vragen
How bad is it really if RLS is off?
Anyone who opens your app can read the key it uses to talk to the database, and with row level security disabled that key returns whatever they ask for. It is not a theoretical risk, it is a public database with extra steps.
Will enabling RLS break my app?
It can, if it is switched on without writing the policies first. That is why I write and test the policies role by role before enforcing them, rather than flipping a switch and hoping.
Do you need my passwords?
No. Invite me to your Supabase project and your repository as a collaborator. If a key must be shared, you rotate it the moment I am done.
Can you work while my app is live?
Yes. Policies are tested against a copy first, and applied in a controlled order so users are never locked out mid-session.
What if my app is on Firebase, not Supabase?
Then this gig is not for you, and I will tell you so rather than learn on your project.
Do I get documentation?
The Hardened package includes a written document with every rule and the reasoning behind it, so your next developer maintains it instead of disabling it.

