Scan free

One free check per repository. Then $1.99.

The free check flags open Supabase RLS, leaked keys and exploited packages. A paid check adds AI Review: it tells you which findings are real and writes a fix prompt that says what to change, what to leave alone, and how to check it worked. Pro keeps watching: up to 5 GitHub repositories scanned again every week, with an email only when a new High or Critical issue appears.

Scan free

What a paid check adds

Free check
Critical

Anyone signed in can read every user's data

supabase/migrations/0002_profiles.sql:12

The access rule on the profiles table allows any logged-in account to select any row. Someone signs up normally, opens the browser console, and reads every email address, phone number and Stripe customer id the app holds. No exploit needed: this is the database doing what it was told.

Blocks launch

Paid check, after AI Review

Confirmed, not a false positive

Confirmed against the migration that created the policy: USING (true) matches every row, so any authenticated user can select any other user's profile.

Change
In supabase/migrations/0002_profiles.sql, drop the permissive select policy on profiles and create one restricted to the owner (auth.uid() = user_id).
Keep
Leave the insert and update policies alone; do not disable RLS on the table to make anything pass.
Check
Sign in as a second user and assert they cannot select the first user's row.

What Pro adds

Your next prompt
Adds a package, a migration, a route. The next weekly scan reads all of it.
Packages you already ship
A flaw found in one after you scanned shows up in the next weekly scan, with nothing changed on your side.

Nothing new, no email. Monitoring scans come on top of your 20 checks a month.

The demo app under Pro monitoring, four weeks. Not your code.
  1. Week 1 First scan done
  2. Week 2 No new High or Critical
  3. Week 3 No new High or Critical
  4. Week 4 1 new High or Critical, emailed

Week 4 email · from Tuvio

1 new High issue in example/demo-shop

The latest scan of example/demo-shop found issues we have not seen in it before.

Vulnerable dependency
1
Get AI review and fixes

Prices

Pay as you go

  • Free check 1 per repository, no card

    $0

    No AI Review

    Scan free
  • Single check 1 check

    $1.99

    Before one launch

    Buy
  • Fix Pack 3 checks

    $4.99

    Scan, fix, scan again

    Buy

Pro, billed monthly

  • Pro 20 checks a month, plus monitoring

    $29.99/mo

    Keeps watching up to 5 repos

    Get Pro
  • Every paid check includes AI Review. Prices are in USD.
  • Buying asks you to sign in first, then goes straight to checkout.
  • Repositories are unlimited on every plan.
  • Monitoring scans don't count against Pro's monthly checks. A private repository needs a read-only GitHub token.
  • Bought checks never expire. Pro's monthly checks lapse at renewal. Cancel Pro any time.
  • Unused checks from a one-off pack are refundable within 14 days. Refund terms

What every check looks at

The same scanners on every plan, free or paid.

Secrets
214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
Dependencies
Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
Code
83 rules for mistakes that work fine until someone looks, plus 344 general rules at Low.
Configuration
Dockerfile, Kubernetes, Terraform, and 27 mobile checks.
See what it covers for your stack

Coming soon

Team

For a repository past what an individual plan fully scans: no file-count limit on code scans, secret scans across full git history, and seats and roles for a team.

Human review

Thirty minutes with an engineer, for the architectural finding no prompt can close.

Tuvio: an audit for the app you did not entirely write.

© 2026 CodexMotive Digital Solutions. Tuvio is a product of CodexMotive. Scanning reads your files; it never runs them.