Ship fastClaude, Codex, Lovable, Base44, Cursor, Supabasestay covered.

Security that runs inside your agency's pipeline, on every project you build for clients.

The stack I specialize in

  • Supabase
  • Clerk
  • Stripe
  • Next.js
  • GitHub

What I actually check.

Same models, same training data, same stack.The mistakes repeat, and that’s what makes them findable.

Is your database enforcing what you think it is?

The deepest check and the one nothing else does. I read your policies against your actual data model and test them as each of your roles.

Two ways I work with agencies.

  • Gate

    The audit before you hand the project over. Every real way the app can be broken into, proven, with the fix.

    Priced per project

  • Monitor

    A one-time install that re-runs the testing on every pull request. No retainer.

    Priced per install

Here’s how I test, how the continuous layer gets installed, and what it looks like on your side when someone pushes code.

Who this is for.

If three of these are true, we should talk.

01 / 05

You ship client MVPs and internal tools fast, on Supabase, using Lovable, Bolt, Cursor or Claude.

See if we’re a fit.

1 / 5

What best describes you

Your details are never shared or sold. See our privacy policy.

Questions I get asked.

If yours is not here, the call is the fastest way to get a straight answer.

  • Generic scanners look for classic vulnerabilities (injection, unsafe eval) that AI-built agency apps rarely contain. They miss the patterns that actually recur on this stack. So I wrote my own rules for those patterns: request data written straight into a database write, a key exposed to the browser, a Stripe webhook that never verifies its signature. On top of that I check your Supabase configuration by hand, which no code scanner can read at all. That’s where the worst issue on this stack lives.

  • You get a specific fix for every finding, not “this is broken.” A code snippet or a configuration change your team or your AI tool can apply directly. Once you’ve applied them, I re-check at no cost to confirm each one actually resolved the issue.

  • That’s exactly what the report says: what was checked and what came back clean. I’d rather tell you it’s solid than manufacture findings to justify the fee. The report also includes the findings I reviewed and dismissed, so you can see a person went through it rather than taking my word for the result.

  • No. The audit stands on its own. The continuous layer is there if you want it once you’re shipping regularly, and it’s a one-time install with no retainer. There’s no requirement to take it, and I won’t chase you for it.

  • Priced per project by complexity for the audit, a one-time fee for the monitoring install, and a wholesale rate per client roster if you resell it. Never per seat, never per hour. I’ll give you real numbers on the call once I know the shape of the app.

  • Yes, deliberately. It’s the reason I find what generalists miss. The deepest check I run reads your database policies against your actual data model, and that’s specific to Supabase. If you’re on something else, tell me on the form and I’ll say honestly whether any of it transfers. I’d rather tell you no than guess on a stack I don’t know.