Postgres & Supabase security audit: RLS + billing by Harrison SongoloPostgres & Supabase security audit: RLS + billing by Harrison Songolo
Postgres & Supabase security audit: RLS + billingHarrison Songolo
Cover image for Postgres & Supabase security audit: RLS + billing
If your app is multi-tenant, row-level security is probably doing less than you think. RLS scopes rows, but it cannot express "this row is yours, the plan column is not" — so a tenant can pass every policy you wrote and still upgrade their own account for free. I found exactly that in my own production platform, and closed it.
What you get😍 A written audit of your Postgres or Supabase schema: RLS policies, privileged columns, and every place the client can write something it should not.
The layered fix: policies, a privileged-column trigger, and security-definer functions the client cannot forge.
Integration tests that run each attack against a real database and assert it fails, so the gap cannot silently reopen.
A walkthrough call so your team can maintain it.
Turnaround is about one week. Best for teams on Supabase or Postgres running subscriptions, plan tiers, or usage limits, where money depends on a column.
Starting at$1,500
Duration1 week
Tags
Node.js
PostgreSQL
Stripe
Supabase
Backend Engineer
Fullstack Engineer
Service provided by
Harrison Songolo proPetaluma, USA
4
Followers
Postgres & Supabase security audit: RLS + billingHarrison Songolo
Starting at$1,500
Duration1 week
Tags
Node.js
PostgreSQL
Stripe
Supabase
Backend Engineer
Fullstack Engineer
Cover image for Postgres & Supabase security audit: RLS + billing
If your app is multi-tenant, row-level security is probably doing less than you think. RLS scopes rows, but it cannot express "this row is yours, the plan column is not" — so a tenant can pass every policy you wrote and still upgrade their own account for free. I found exactly that in my own production platform, and closed it.
What you get😍 A written audit of your Postgres or Supabase schema: RLS policies, privileged columns, and every place the client can write something it should not.
The layered fix: policies, a privileged-column trigger, and security-definer functions the client cannot forge.
Integration tests that run each attack against a real database and assert it fails, so the gap cannot silently reopen.
A walkthrough call so your team can maintain it.
Turnaround is about one week. Best for teams on Supabase or Postgres running subscriptions, plan tiers, or usage limits, where money depends on a column.
$1,500