Methodology, scope & privacy

What an audit is, what it reads, and the lines it never crosses.

The method

Severity rubric

SeverityMeaning
CriticalExposed credentials or anything that bypasses RLS entirely — act immediately.
HighUser data readable/writable by anonymous key holders.
MediumIntegrity loss among authenticated users.
LowPublic-read on data that appears intentionally public — flagged, not counted against you.

A finding is never reported without the verify query that lets you confirm it independently. No claims without evidence.

Scope — what an audit is not

Privacy commitments (non-negotiable)

Who does this

Cenk Kurtoglu — engineer, audits Supabase RLS setups. Public method: supabase-rls-leak-demo · field notes on dev.to/cekuu35. One human, no subcontractors.