Protect Your Supabase Data

Automated penetration testing that finds RLS bypasses, auth flaws, and exposed data before attackers do.

Full vulnerability scan with all attack vectors
+ Add anon key (optional, for deeper testing)

Your Supabase anon/public key enables deeper security testing

[!] Only test projects you own or have explicit authorization to test

01 Discover 02 Execute 272+ attacks 03 Get fixes
272+ vectors 10 categories

Preview

Example of scan results

See credential discovery, schema analysis, vulnerability findings, and sensitive data detection in one dashboard.

Exemplo da interface de resultados do scan: terminal com logs, painel de vulnerabilidades e schema descoberto
! Authorized testing only — test projects you own or have permission to test.

Coverage

272+ vectors across 10 categories

Every Supabase attack surface tested with real exploitation attempts.

RLS Bypass — Row Level Security policy circumvention
critical
Authentication — Token leaks, session hijacking
critical
Business Logic — IDOR, price manipulation
high
AI-Generated Code — LLM mistakes, exposed keys
critical
Injection — SQL injection, XSS vectors
critical
Secrets Exposure — GraphQL, Vault, API keys
high
Multi-tenancy — Tenant isolation failures
critical
Database Access — Privilege escalation
critical
Realtime & WS — WebSocket hijacking
medium
Operations — Backup exposure, logging
medium

Ready to secure your Supabase project?

Create a free account.