Methodology, scope & privacy
What an audit is, what it reads, and the lines it never crosses.
The method
- Catalog pass: every table × every policy, rated missing / permissive / correct — with the 30-second verify query for each non-clean row.
- Secrets pass: repo-wide sweep for committed
service_role JWTs and sb_secret_ keys. Rotating always comes before reporting.
- Grants pass (full tier): table grants, role attributes, and API/schema exposure — RLS is the row-level gate; grants are the gates around it.
- Write-path simulation (full tier): your schema runs on a local PGlite fixture; a two-user isolation suite proves which paths actually leak — the same runnable pattern as the public demo.
- Report: severity-ranked findings (Critical / High / Medium / Low), each with verify-SQL, the fix, and estimated fix-hours. Remediation quoted separately, from the report.
Severity rubric
| Severity | Meaning |
| Critical | Exposed credentials or anything that bypasses RLS entirely — act immediately. |
| High | User data readable/writable by anonymous key holders. |
| Medium | Integrity loss among authenticated users. |
| Low | Public-read on data that appears intentionally public — flagged, not counted against you. |
A finding is never reported without the verify query that lets you confirm it independently. No claims without evidence.
Scope — what an audit is not
- A surface scan of public source is exactly that: it can miss runtime configuration, edge functions, storage rules, and anything not in the repo.
- An audit is not a penetration test and not a compliance certification.
- Policy-count or
rls_enabled signals alone never prove an externally exploitable leak — grants and exposure are always part of the verdict.
Privacy commitments (non-negotiable)
- Public source only. The free check runs in your browser and reads public GitHub files. Paid audits read what you choose to share — repo access you grant, or files you send.
- Never your database. No audit connects to your live Supabase project. Write-path simulation happens on a local fixture with synthetic data.
- Never your secrets. No service-role keys, no seed phrases, no credentials — if anyone asks you for those (including someone claiming to be me), it's not me.
- Unproven claims go nowhere. If I notice an issue in someone's public repo, the flow is: read public source, verify precisely, then one private, informative note to the owner. Nothing is published without proof and permission.
- Your data isn't stored. The free check keeps nothing. Audit correspondence stays in email until you ask otherwise.