TrustBoost shield logo TrustBoost / vibe-code security

Find what your app left unlocked, before someone else does.

Apps built with Lovable, Bolt or Base44 ship in minutes — but most leave at least one Supabase table readable by anyone. Paste your URL and know in under a minute.

No signup Read-only Your code stays untouched

FREE SCAN

Check your Supabase project

Project Settings → API → "anon public" in your Supabase dashboard. Never paste your service_role key.
1
Looking for exposed tables
2
Testing anonymous read access on each
3
Scoring the severity of what we found
RESULT
0tables checked
0with findings

This is exactly how we reproduce the mistake that exposes your data.

01

We look for your tables

We try the table names most common in real apps — the same starting point anyone with your public URL would have.

02

We request a sample

Using the same public key already sitting in your browser's code — nothing a normal visitor couldn't also do.

03

We score how serious it is

If something responds, it goes through our sensitive-data classifier to tell you whether it's noise or a real problem.

Why this matters right now

2026 security research found hundreds of apps built with these tools exposing full user records because of a single security policy left off. The pattern keeps repeating because AI tools generate the connection to the database, but don't always turn on the permission layer.