AI platforms · backend platform used by most AI builders
Is my Supabase app secure?
Supabase is secure when row-level security is on and the policies are right. AI builders routinely turn RLS off to make a query work, write policies that allow everyone, or reach for the service-role key in the browser. Kavach checks the migrations, the client code and the live site.
Audit my Supabase app free → Scan the code too
What Supabase usually leaves open
Typical stack: Postgres with row-level security, auth, storage and edge functions; the anon key lives in the browser.
- Row-level security disabled or policy allows everyone (Code Scan)disable row level security, or a policy with using (true) or with check (true), in a migration.
- Server-only key referenced in client code (Code Scan)The service-role key referenced in front-end code.
- Secret exposed through a browser-public env prefix (Code Scan)A server-only key stored under a public env prefix such as VITE_ or NEXT_PUBLIC_.
- Storage object or bucket made public (Code Scan)A storage bucket or object made public that should be served through signed URLs.
- CORS allows any origin (Code Scan)An edge function that answers any origin.
How to fix it in Supabase
Run the scan, then paste this into Supabase together with the Kavach report. It tells the assistant exactly what to do and what not to touch.
Audit my Supabase usage. 1) For every table, confirm RLS is enabled and show me the policies; rewrite any using (true) policy to compare auth.uid() with the owner column. 2) Remove the service_role key from all client code and move those operations to an edge function. 3) Check every public env variable for secrets. 4) Make buckets private and use signed URLs. Show the SQL and code for each change.Re-scan when it is done. The grade and the findings list show whether the change took, and monitoring tells you if a later prompt reopens anything.
Questions about Supabase security
Is the Supabase anon key a secret?
No. It is designed to be public. Row-level security is what protects the data; the anon key with RLS off is equivalent to a public database.
What does using (true) in a policy mean?
That the policy allows every row for everyone the policy applies to. For SELECT on public content that can be intended; for UPDATE, DELETE or anything personal it is a data leak.
Can Kavach see my Supabase project?
No. Kavach reads your migrations and code from the archive you upload and looks at the public site. It never connects to your database.
Where do I find my migrations?
In the supabase/migrations folder of an exported project. Lovable, Bolt and v0 projects that use Supabase all include it when exported to GitHub.
Other platforms
Lovable · Bolt · v0 · Replit Agent · Cursor · Claude Code · Firebase · Vibe coding security scanner
Kavach reports observations from read-only checks, not guarantees; see the disclaimer. Supabase is a trademark of its owner; Kavach is not affiliated with it.