Gitrex Technologies

Reviews

Security & database review: RLS policies, keys, and access rules

A focused review for teams that mainly need the data layer verified. We check whether your Supabase or Postgres row-level security actually restricts what it should, whether keys and secrets are exposed to the browser, and whether your endpoints trust the wrong callers — then explain each finding in plain language.

What it is

Security & Database Reviews, in plain terms

The specialty behind the audit: row-level security policies, exposed keys, access rules, endpoint security. A focused review for teams who mainly need the data layer verified — read-only access, NDA on request.

Who it’s for

A good fit if you are…

  • Teams on Supabase who are not sure their RLS policies hold up
  • Products about to store customer data, health data, or payments
  • Developers who want an independent second pair of eyes on access control before launch
What’s included

What the work covers

  • Row-level security policy review against real user roles and scenarios
  • Exposed API keys, service-role keys, and client-side secrets
  • Authentication, session, and authorisation checks on every endpoint
  • Storage bucket rules and file access
  • Edge functions, webhooks, and server actions that trust unverified input
  • Findings ranked by severity with concrete fixes
Questions

Security & Database Reviews: common questions

How is this different from the AI App Launch Audit?
The audit covers the whole build — code quality, deployment, payments, maintainability. The security and database review goes deeper on one thing: whether the data layer and its access rules are safe.
What access do you need?
Read-only access to the repository and the database schema and policies. An NDA is available on request before access is shared.
Which databases and platforms do you review?
Primarily Supabase and Postgres, including RLS policies, storage rules, and edge functions, plus the Next.js or React front end that talks to them. Firebase security rules can be reviewed on request.
Do you fix what you find?
The report is written so your own developer can. If you would rather we did, the fixes can be scoped as a short sprint.
From the blog

Read before you hire anyone

Not sure this is the right engagement?

Tell us what you’re building and where it’s stuck. You’ll get a straight answer about which of these — if any — you actually need.

Prefer email? sales@gitrextechnologies.com