Supabase security guides
Plain-language guides to Supabase and Postgres security: row level security, policies, keys, and what to check before you launch.
Supabase Security Checklist for Production AppsA practical Supabase security checklist: RLS on every table, role-scoped policies, the service role key, functions, views, storage and auth settings.
Supabase Row Level Security (RLS) ExplainedHow Supabase row level security works, why the anon key makes it mandatory, USING vs WITH CHECK, common policy mistakes and a correct owner-only policy.
Is My Supabase Database Exposed? How to CheckCheck whether your Supabase database is exposed: what the anon key allows, SQL to list tables without RLS, how to test as a visitor, and how to fix it.
Securing AI-Built Supabase Apps Before LaunchWhy apps built with AI code generators on Supabase often ship without working row level security, the usual mistakes, and what to check before launch.
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.