Apps built with Lovable, Bolt or Base44 ship in minutes — but most leave at least one Supabase table readable by anyone. Paste your URL and know in under a minute.
Check your Supabase project
We try the table names most common in real apps — the same starting point anyone with your public URL would have.
Using the same public key already sitting in your browser's code — nothing a normal visitor couldn't also do.
If something responds, it goes through our sensitive-data classifier to tell you whether it's noise or a real problem.
2026 security research found hundreds of apps built with these tools exposing full user records because of a single security policy left off. The pattern keeps repeating because AI tools generate the connection to the database, but don't always turn on the permission layer.
This scanner performs read-only checks against publicly reachable Supabase endpoints, using the anonymous key already exposed in your app's client-side code.
You may only scan a project you own, or one you have explicit permission to test. Scanning a third party's project without authorization is not permitted, and access attempts are logged.
If you purchase a fix, we will never ask for your service_role key as a first step. You'll receive the exact SQL to run yourself in your own Supabase SQL editor, with guidance, and we re-verify the result using the same read-only scan. Hands-on access, if ever needed, is granted temporarily and only with your explicit approval.
Results are best-effort and based on common table names and default configurations. A clean scan does not guarantee your application has no security issues — it is not a substitute for a full professional security audit.
Paid reports and fixes are processed by a third-party payment provider. We do not receive or store your card details.
We may keep anonymized, aggregate figures (for example, "X% of scanned tables lacked a security policy") for research and public write-ups. These never identify your project or organization.
You can request deletion of any contact information we hold about you at any time by reaching out through the contact details provided at checkout.
TrustBoost provides an automated, best-effort security scan for Supabase-backed applications, plus optional paid detailed reports and remediation.
The scan and any report are provided "as is," without warranty of completeness or accuracy. They do not constitute a professional security audit or legal compliance certification.
To the maximum extent permitted by law, TrustBoost is not liable for indirect, incidental, or consequential damages arising from use of this tool or reliance on its results.
Paid reports and fixes are one-time purchases. Refund terms are shown at checkout before payment.
These terms are governed by the laws of Colombia, without regard to conflict-of-law principles.