cd /news/ai-safety/free-scanner-for-exposed-supabase-da… · home topics ai-safety article
[ARTICLE · art-134954] src=api.trustboost.dev ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Free scanner for exposed Supabase data in AI-built apps (Lovable, Bolt, Base44)

TrustBoost launched a free read-only scanner that checks Supabase-backed apps built with Lovable, Bolt, and Base44 for exposed database tables, using the anonymous key already present in an app's client-side code. The company said 2026 security research found hundreds of apps built with these tools exposing full user records because a single security policy was left off, a pattern it attributes to AI tools generating the database connection without always enabling the permission layer. TrustBoost offers optional paid detailed reports and remediation, delivers fixes as SQL the owner runs in their own Supabase SQL editor, and states it never asks for the service_role key as a first step.

read2 min views1 publishedSep 20, 2026

Apps built with Lovable, Bolt or Base44 ship in minutes — but most leave at least one Supabase table readable by anyone. Paste your URL and know in under a minute.

Check your Supabase project

We try the table names most common in real apps — the same starting point anyone with your public URL would have.

Using the same public key already sitting in your browser's code — nothing a normal visitor couldn't also do.

If something responds, it goes through our sensitive-data classifier to tell you whether it's noise or a real problem.

2026 security research found hundreds of apps built with these tools exposing full user records because of a single security policy left off. The pattern keeps repeating because AI tools generate the connection to the database, but don't always turn on the permission layer.

This scanner performs read-only checks against publicly reachable Supabase endpoints, using the anonymous key already exposed in your app's client-side code.

You may only scan a project you own, or one you have explicit permission to test. Scanning a third party's project without authorization is not permitted, and access attempts are logged.

If you purchase a fix, we will never ask for your service_role key as a first step. You'll receive the exact SQL to run yourself in your own Supabase SQL editor, with guidance, and we re-verify the result using the same read-only scan. Hands-on access, if ever needed, is granted temporarily and only with your explicit approval. Results are best-effort and based on common table names and default configurations. A clean scan does not guarantee your application has no security issues — it is not a substitute for a full professional security audit.

Paid reports and fixes are processed by a third-party payment provider. We do not receive or store your card details.

We may keep anonymized, aggregate figures (for example, "X% of scanned tables lacked a security policy") for research and public write-ups. These never identify your project or organization.

You can request deletion of any contact information we hold about you at any time by reaching out through the contact details provided at checkout.

TrustBoost provides an automated, best-effort security scan for Supabase-backed applications, plus optional paid detailed reports and remediation.

The scan and any report are provided "as is," without warranty of completeness or accuracy. They do not constitute a professional security audit or legal compliance certification.

To the maximum extent permitted by law, TrustBoost is not liable for indirect, incidental, or consequential damages arising from use of this tool or reliance on its results.

Paid reports and fixes are one-time purchases. Refund terms are shown at checkout before payment.

These terms are governed by the laws of Colombia, without regard to conflict-of-law principles.

── more in #ai-safety 4 stories · sorted by recency
── more on @trustboost 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/free-scanner-for-exp…] indexed:0 read:2min 2026-09-20 ·