RowShield
Security checks for AI-built Supabase apps

Your AI wrote the schema.
Nobody wrote the policies.

AI-built Supabase apps ship fast. RowShield checks the public surface, RLS policies, leaked keys and schema drift before they become incidents.

Run a free read-only audit

Paste a deployed app URL. No account or database writes required.

No signup

Use the URL of your deployed app. RowShield reads the public bundle to discover its Supabase connection.

Optional: paste your Supabase anon or publishable key

Anon/publishable keys only. Never paste a service_role key.

Read-only. The scanner never issues a write, and nothing you enter is stored.

GET, HEAD and OPTIONS onlyRows are never storedUsually under 10 seconds

Keep watching after launch

Find the hole. Track the drift. Fix it.

RowShield turns a one-time security check into a signal you can keep acting on.

Scheduled policy scans

RLS, storage, key exposure and policy-performance checks run on the cadence your plan needs.

Drift you can act on

See what appeared, came back after a fix, or disappeared instead of reading the same report every time.

Alerts on transitions

Slack, Discord, email or webhooks notify you when a finding changes state, not every time a scan runs.

Start with the failures that matter

Each finding comes with the SQL that fixes it, generated from your actual columns.

criticalRow Level Security disabled

Any table reachable through PostgREST with RLS disabled is world-readable to anyone holding the anon key — which ships in your client bundle and is public by design. Every row is exposed.

RLS_DISABLED
criticalPolicy always evaluates to true

A permissive policy whose expression is a constant true grants the whole table to every role it targets. RLS is enabled, so the dashboard reports the table as protected while it is wide open.

RLS_TAUTOLOGY
criticalservice_role key shipped to the browser

The service_role key bypasses RLS entirely. Once it is in a client bundle it is public, and every policy in the project is decorative. Rotate the key immediately and move the calls that need it behind a server route.

SERVICE_ROLE_KEY_EXPOSED
View all detection rulesNine checks across your catalog and public surface.

Continuous monitoring

Keep your security check running after launch

Start with the free audit, then choose a monthly monitoring plan when you want RowShield watching the catalog for you.

RowShield Indie

$29 / month

or $290/yr

For one developer shipping fast.

  • Up to 3 projects
  • Hourly scans
  • Email and Slack alerts
  • 1 seat
  • Full findings and remediation SQL

RowShield Team

$99 / month

or $990/yr

For a team that has customers to answer to.

  • Up to 15 projects
  • 15-minute scans
  • Email, Slack, Discord and custom webhooks
  • Unlimited team seats
  • Full findings and remediation SQL

RowShield Growth

custom
from $279 / month

For agencies and platforms monitoring many customer projects.

We go live August 31, 2026

Enter your email and we’ll notify you the moment your plan goes live — the free audit is available today.

Founding customers (first 100) lock in 25% off annual forever.

Start here

Check your public Supabase surface

Run the free read-only audit on a deployed app. No account, database writes or configuration are required.

Supabase security monitoring for AI-built apps | RowShield