Night watch
Know the day your database opens up
Your AI tool keeps adding tables, policies and functions while you build, and one of them can end up open to anyone with the key in your web page. About once a day we check what your Supabase database lets a stranger do, and write to you when a check finds something new open, with the line your database returned and, where it follows from your schema, the migration that closes it.
$49.00one Supabase project, 12 months
Full refund within 14 days of payment, or if the watch cannot connect to your project at setup and we cannot fix that together. Refund policy.
Who it is for
It needs a Supabase project you own: you create a role in the SQL editor and paste the connection string from the Supabase dashboard. Lovable Cloud and Bolt Cloud keep the project in their own account and do not give out a connection string, so the watch cannot run there yet. Supabase's own Security Advisor is free and emails project owners about several of the same problems. The watch adds the line your database returned, who can actually use it and, where it follows from your schema, the migration that closes it; it also lists the tables anyone can read, so you can say whether that is on purpose.
How it starts
- Pay below. The order page opens.
- Run the SQL the order page shows in your Supabase SQL editor. It creates a role that is granted nothing and cannot read or change your tables.
- Paste your Session pooler connection string. The first check runs right away and shows you everything that is open today.
What the role can and cannot do
- It is granted nothing: no table, no other role, no schema to create in. Before every check we ask your database what it can do. If it could read or change a table, act as another role, own anything, or reach a service-role key kept in a webhook or a function, we stop the watch and delete its password.
- Like every role in Postgres, it can read your schema: table and column names, policies, grants, function source and trigger definitions. It can also call what your database opens to every role; at setup we list the SECURITY DEFINER functions among those, with the one line that closes each.
- Each check is two queries of the Postgres catalog in a read-only transaction. We never read a table and never call your functions.
- It expires by itself a month after the watch ends. Stop it any time from the order page, and remove it with
drop role auditai_watch;
What we keep
Your project's pooler host and ref, the role's password encrypted with a key that is not stored next to it, and what the checks found: the names of the tables, policies and functions that are open, with the fix. Not your data, and not the snapshot a check is made from. Stopping the watch deletes the password and everything it recorded.
What it does not check
Your application code: a route on your own server that uses the service-role key ignores every rule the database has. The watch reads the database only; the repository scan reads the code. Try the same check once for free first: what can a stranger read in your database?