Observed arrival · 2026-09-11
Kloof’s skeptical security report for Supabase
Kloof reviews Supabase schemas and edge functions, then delivers dated, human-reviewed security evidence rather than a certification.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
Field notes
Kloof accepts a read-only app repository or zip and runs a named battery across Supabase’s Postgres/RLS, storage, edge-function authorization, and secret-handling surfaces. The page says gitleaks is included by default and Semgrep can be added on request. Its output is a signed PDF with a verdict, ranked findings, and remediation order, with standard delivery stated as five business days and no production or service_role access.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
$PaidCommerce or pricing visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue