Prove your users' data is private.
AI built your app. SafetyVibe shows whether a stranger can read your customers' data — with evidence, not guesses.
Scan a URL
Enter your app's address for a passive check — like View Source. It detects whether your app uses Supabase and whether any key is exposed in the shipped code. No attack is made and no login is needed.
Deep-test my app
The real proof: connect your Supabase project and two test logins, and we check whether user A can read user B's private rows. This runs a live cross-account test and takes about 15–20 seconds.
See a live demo
No app of your own handy? Run the full proof against a real Supabase we host — a broken table where any logged-in user can read everyone's rows, and a correctly secured one. Same engine as the deep test: two users, a cross-account read, evidence, and the fix.
Deterministic proof, not a warning. Deep cross-account testing requires connecting your own app and your authorization. Tailnet-only demo.