RedScore.ai
All posts
Security Scanners

What is a Supabase security scanner?

A Supabase security scanner checks public signals on the domain your app runs on. TLS, headers, DNS, email auth, exposure. Not RLS or database rules.

1 min read · 2026-06-08 · RedScore Research Team

Quick answer

A Supabase security scanner checks the public posture around your app's live domain: TLS, headers, DNS, email authentication, and exposure signals. It does not read Supabase RLS policies, API keys, or Firestore-style database rules.

What does a Supabase security scanner check today?

The hostname your users type into the browser. TLS and certificates, security headers, DNS hygiene, email authentication, cookies, and public exposure signals.

Supabase teams usually worry about RLS and leaked keys first. Fair. But buyers and random scanners still look at your public domain before they ever see your database console. Weak headers and missing DMARC still make you look sloppy in a security review.

RedScore scans from the outside in about 60 seconds. No Supabase credentials required.

What is this not?

Not an RLS audit. Not an API key hunt in your repo. Not a review of your Supabase Auth settings.

If you need database rule testing, that is a different job with different access. This scan answers a simpler question: what does the internet already see on your production domain?

How do I scan a Supabase-backed app?

  1. Pick your production domain, not the Supabase project URL.
  2. Go to /lookup and enter that production domain.
  3. Read the category grades and fix-first summary on the report.
  4. Close public gaps before launch, payments, or a customer questionnaire.

Do the outside-in pass first. It is free and fast. Then go deeper on backend rules if you still need to.

Frequently asked questions

Does RedScore scan Supabase RLS policies?

No. The free scan is outside-in only. RLS and table policy checks need project access RedScore does not ask for on the free scan.

Do I need my Supabase service key?

No. Enter the public domain your users visit, not your `*.supabase.co` project URL.

Will this work for vibe-coded Supabase apps?

Yes. If the app has a public production domain, RedScore can scan it. Lovable, Bolt, and Cursor setups included.

What should I fix first?

Public gaps on your production hostname: headers, TLS, email spoofing risk, DNS hygiene. Fix those before you obsess over console settings.

Run a free outside-in scan on your domain in about 60 seconds.

Scan domain