Fix & re-check
We write the migration. You apply it. We check again.
The free database check shows what a stranger can read or change in your Supabase database and, where it follows from your schema, the migration that closes it. If you would rather not work out the SQL yourself, we write one migration for everything it found, with the lines that undo it, and check your database again after you apply it.
$149one Supabase database, one time
How it works
- Run the free database check and keep the result you pasted.
- Email it to hello@auditai.sh as an attachment, with a few words on your app: what anyone may see, what only signed-in users may see, and what only the owner of a row may see.
- Within one working day we reply with an invoice: CryptoBot, or USDT on TRON or TON.
- Within two working days of payment you get one migration file. Every statement has a comment saying what it closes and who it still lets in, and it comes with the lines that undo it and a read-only query that shows the result.
- You run it, on a branch or a copy first if you have one, and send us a new result of the same check. We tell you what is still open.
We tested the check's migrations on 34 real Supabase schemas rebuilt from public repositories: all 243 applied cleanly, closed their hole when the database was checked again, and their undo lines restored access as it was.
What we need, and what we don't
- Only the check's result: names, rules, grants and the source of your SECURITY DEFINER functions. Never a row of your data.
- No password, no key, no access to your project. We never connect to your database; you run every statement yourself.
- We draft the migration with the help of an AI model (Anthropic's Claude), which sees the snapshot you send and nothing else, and we check every line against your snapshot before it goes to you.
- Your application code stays with you. A route on your own server that uses the service-role key ignores every rule in the database, so this does not cover it.
If it does not work
Full refund if the re-check shows the same hole still open after you applied our migration as written, if we cannot write one for your database, or if you cancel before we deliver. A policy that is too tight can stop your own app from reading its data; each statement says what it changes so you can test it, and the undo lines put things back. Full terms and refund policy: terms of sale.
Get it fixed
Email the check's result to hello@auditai.sh. Built with Lovable Cloud or Bolt Cloud and cannot open the Supabase SQL editor? Write anyway and tell us; we will say honestly whether we can help.