Scan free

See what's exposed in your Supabase tables, .env file, git history and Firebase rules.

Tuvio reads the repo your assistant wrote, flagging open Supabase RLS, leaked keys, exploited packages and mobile config mistakes.

First check free on every repository. No account, no card.

A demo app built with Next.js, Supabase and Stripe. Not your code.

Security findings

4 things here can be used against you as the code stands today.

  • CriticalAnyone signed in can read every user's datasupabase/migrations/0002_profiles.sql
  • CriticalAnyone can fake a successful paymentapp/api/webhooks/stripe/route.ts
  • HighThe admin check only runs in the browserapp/api/admin/users/route.ts
  • HighA secret key may be hardcoded in the codelib/cache.ts

Easy to ship. Hard to spot.

  • One customer logs in and reads every other customer's rows.

    Supabase row-level security

  • Your service-role key ships to every browser.

    NEXT_PUBLIC_, VITE_, EXPO_PUBLIC_

  • The admin check only exists in the page.

    "use client" components

  • Change the ID in the URL, read someone else's record.

    API routes

  • A server action writes to your database for anyone.

    "use server" functions

  • Anyone can fake a "payment succeeded" and get your paid plan free.

    Stripe webhooks

  • The key you deleted is still in git history.

    Every commit, not just the latest*

  • A package in your app has a flaw attackers are already exploiting.

    Your lockfile

Every check also covers other known vulnerabilities in your dependencies, Docker and infrastructure config, and injection and crypto mistakes across the code.

All coverage

Why not just ask your assistant?

You deleted the key. Git kept it.
Your assistant reads the files you have now. Anyone who clones your repo can read the history. We scan it.*
You have to know what to ask.
"Check my security" gets you a generic list. We check what you've never heard of: your Firebase rules, your Android signing keys, the secrets in your Expo config.
Ask twice, get two lists.
Same commit, same findings, every time. When one disappears, you fixed it.
It doesn't know last month's news.
An assistant knows about broken packages up to the day it was trained. We check yours against a list we update every week.
It won't check again next week.
An assistant answers when you ask. Pro scans your repo again every week and emails you when a new High or Critical issue turns up.

Don't take our word for it. Ask your assistant first, then run the free check on the same repo and compare. What an assistant is good at is judging what we found — that's AI Review.

The full answer

Then AI Review tells you which ones are real.

Included with every paid scan, from $1.99. It drops the ones that aren't real, puts the rest in order, and writes the fix as a prompt for Cursor or Claude Code.

A secret key may be hardcoded in the codelib/cache.ts

Not a blocker. The value is a cache label, not a password.

Fix prompt for the first finding

In supabase/migrations/0002_profiles.sql the row-level security policy on profiles uses USING (true), which lets any authenticated user select every row. Write a new migration that drops that policy and creates one restricted to the owner (auth.uid() = user_id). Leave the insert and update policies alone. Then add a test that signs in as a second user and asserts they cannot select the first user's row. Do not disable RLS to make anything pass.

A clean report is true for one commit.

You'll keep prompting, and packages you already use will keep turning up on the exploited list. Pro scans your repositories again every week and emails you only when something new and serious appears. Nothing new, no email.

It runs every week without you.
Up to 5 GitHub repositories, public or private. A private one needs a read-only access token.
It doesn't use your checks.
Monitoring scans come on top of Pro's 20 checks a month.
You only hear about what's new.
The first scan sets the baseline. After that, an email means a High or Critical issue that wasn't there last week.
The email leads to the fix.
It links to the report, where AI Review confirms what's real and writes the fix prompts.
See Pro · $29.99 USD / month
The demo app under Pro monitoring, four weeks. Not your code.
  1. Week 1 First scan done
  2. Week 2 No new High or Critical
  3. Week 3 No new High or Critical
  4. Week 4 1 new High or Critical, emailed

Week 4 email · from Tuvio

1 new High issue in example/demo-shop

The latest scan of example/demo-shop found issues we have not seen in it before.

Vulnerable dependency
1
Get AI review and fixes

What happens to your code.

It is read, never run.
Nothing is built or installed, so no postinstall script from your repo, or from anything it depends on, runs on our machines.
AI Review sees findings, not your whole repository.
Each finding and the few lines of code it points to. Only on paid scans, sent to Anthropic, with any credential masked before it leaves.
Delete means delete.
Closing your account removes projects, scan history and repository tokens.
The copy is deleted when the check ends.
We clone the repository, scan it and delete the clone. The few lines each finding points to are kept for 30 days so AI Review can read them, then deleted.

A clean report means these tools found nothing blocking on that commit. That is a good sign and we will never call it a guarantee. Nothing here edits your code or opens pull requests. Accessibility is out of scope because testing it means running your app, so it has its own tool at codexmotive.com/audit.

Find out tonight, before your users do.

Scan free

One free check per repository. No card. Compare plans

Tuvio: an audit for the app you did not entirely write.

© 2026 CodexMotive Digital Solutions. Tuvio is a product of CodexMotive. Scanning reads your files; it never runs them.