Vigavo for Supabase

Supabase, locked down.We stay awake.

We check whether your anon key can read or write tables it should not, list your public buckets, and back up your Postgres database every day.

Free. No signup. Read-only checks from the outside.

What we check on Supabase

Most Supabase leaks are a missing or too-open Row Level Security policy. We test it the way an attacker would, with your public anon key only.

  1. Row Level Security

    Tables readable or writable with the anon key are flagged with the exact table name and a policy skeleton.

  2. Storage buckets

    Public buckets that list their files are reported, with what can be listed.

  3. Daily verified backups

    Connect in one click with a read-only role. Each snapshot is restored on our side to prove it works.

Everything a small team forgets to check

Findings ranked by what an attacker would try first, with the fix right next to each one.

Scan like an attacker, safely

Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.

Watch for changes

Scheduled scans compare against the last result, so you hear about a new leak once, not every day.

Backups that restore

Encrypted database snapshots, verified by an actual restore and row counts.

Fix prompts

Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.

Alerts without noise

Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.

Questions

Will the scan change my data?

No. Read probes only. The write probe is off unless you authorize it for your own project, and it cleans up after itself.

Which key do you use?

Only the public anon key your site already ships to every visitor. Never your service role key.

Can you back up Auth users and Storage?

The database backup includes the public, auth and storage schemas. File backups of Storage buckets are on the roadmap.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

What do you store?

The scan result. Free scans are deleted after 30 days.

Feedback
Type