Skip to the card

Card 428 of 10002026-09-11 issue

Observed arrival · 2026-09-11

Kloof’s skeptical security report for Supabase

kloof.dev Observed source
Editorial interest 84/100 Selection signal · not a rating of the site

Kloof reviews Supabase schemas and edge functions, then delivers dated, human-reviewed security evidence rather than a certification.

Landing page captured for the 2026-09-11 issue.

Field notes

Kloof accepts a read-only app repository or zip and runs a named battery across Supabase’s Postgres/RLS, storage, edge-function authorization, and secret-handling surfaces. The page says gitleaks is included by default and Semgrep can be added on request. Its output is a signed PDF with a verdict, ranked findings, and remediation order, with standard delivery stated as five business days and no production or service_role access.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
LoginAccess appeared gated
$PaidCommerce or pricing visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use

One card from the complete issue

Projection by Pedal

381,023 arrived 1,000 judged 1000 catalogued Enter the complete issue
kloof.dev

Landing page observed 2026-09-11. The live site may have changed.