See what's exposed in your Supabase tables, .env file, git history and Firebase rules.
Tuvio reads the repo your assistant wrote, flagging open Supabase RLS, leaked keys, exploited packages and mobile config mistakes.
First check free on every repository. No account, no card.
Security findings
4 things here can be used against you as the code stands today.
- CriticalAnyone signed in can read every user's datasupabase/migrations/0002_profiles.sql
- CriticalAnyone can fake a successful paymentapp/api/webhooks/stripe/route.ts
- HighThe admin check only runs in the browserapp/api/admin/users/route.ts
- HighA secret key may be hardcoded in the codelib/cache.ts
Easy to ship. Hard to spot.
One customer logs in and reads every other customer's rows.
Supabase row-level security
Your service-role key ships to every browser.
NEXT_PUBLIC_, VITE_, EXPO_PUBLIC_
The admin check only exists in the page.
"use client" components
Change the ID in the URL, read someone else's record.
API routes
A server action writes to your database for anyone.
"use server" functions
Anyone can fake a "payment succeeded" and get your paid plan free.
Stripe webhooks
The key you deleted is still in git history.
Every commit, not just the latest*
A package in your app has a flaw attackers are already exploiting.
Your lockfile
Every check also covers other known vulnerabilities in your dependencies, Docker and infrastructure config, and injection and crypto mistakes across the code.
See what it catches in your stack
All coverageWhy not just ask your assistant?
- You deleted the key. Git kept it.
- Your assistant reads the files you have now. Anyone who clones your repo can read the history. We scan it.*
- You have to know what to ask.
- "Check my security" gets you a generic list. We check what you've never heard of: your Firebase rules, your Android signing keys, the secrets in your Expo config.
- Ask twice, get two lists.
- Same commit, same findings, every time. When one disappears, you fixed it.
- It doesn't know last month's news.
- An assistant knows about broken packages up to the day it was trained. We check yours against a list we update every week.
- It won't check again next week.
- An assistant answers when you ask. Pro scans your repo again every week and emails you when a new High or Critical issue turns up.
Don't take our word for it. Ask your assistant first, then run the free check on the same repo and compare. What an assistant is good at is judging what we found — that's AI Review.
The full answerThen AI Review tells you which ones are real.
Included with every paid scan, from $1.99. It drops the ones that aren't real, puts the rest in order, and writes the fix as a prompt for Cursor or Claude Code.
A secret key may be hardcoded in the codelib/cache.ts
Not a blocker. The value is a cache label, not a password.
In supabase/migrations/0002_profiles.sql the row-level security policy on profiles uses USING (true), which lets any authenticated user select every row. Write a new migration that drops that policy and creates one restricted to the owner (auth.uid() = user_id). Leave the insert and update policies alone. Then add a test that signs in as a second user and asserts they cannot select the first user's row. Do not disable RLS to make anything pass.
A clean report is true for one commit.
You'll keep prompting, and packages you already use will keep turning up on the exploited list. Pro scans your repositories again every week and emails you only when something new and serious appears. Nothing new, no email.
- It runs every week without you.
- Up to 5 GitHub repositories, public or private. A private one needs a read-only access token.
- It doesn't use your checks.
- Monitoring scans come on top of Pro's 20 checks a month.
- You only hear about what's new.
- The first scan sets the baseline. After that, an email means a High or Critical issue that wasn't there last week.
- The email leads to the fix.
- It links to the report, where AI Review confirms what's real and writes the fix prompts.
- Week 1 First scan done
- Week 2 No new High or Critical
- Week 3 No new High or Critical
- Week 4 1 new High or Critical, emailed
1 new High issue in example/demo-shop
The latest scan of example/demo-shop found issues we have not seen in it before.
- Vulnerable dependency
- 1
What happens to your code.
- It is read, never run.
- Nothing is built or installed, so no
postinstallscript from your repo, or from anything it depends on, runs on our machines. - AI Review sees findings, not your whole repository.
- Each finding and the few lines of code it points to. Only on paid scans, sent to Anthropic, with any credential masked before it leaves.
- Delete means delete.
- Closing your account removes projects, scan history and repository tokens.
- The copy is deleted when the check ends.
- We clone the repository, scan it and delete the clone. The few lines each finding points to are kept for 30 days so AI Review can read them, then deleted.
A clean report means these tools found nothing blocking on that commit. That is a good sign and we will never call it a guarantee. Nothing here edits your code or opens pull requests. Accessibility is out of scope because testing it means running your app, so it has its own tool at codexmotive.com/audit.
Find out tonight, before your users do.
One free check per repository. No card. Compare plans