Security Engine v4.2.0-stable
99.9% Audit Accuracy

Supabase RPC Security Infrastructure

Supabase RPC Vulnerability Scanner: Secure Your API

Scan your Supabase Remote Procedure Calls (RPC) for security flaws and unauthorized access paths.

Securing databases for engineers from

SUPABASENEONPRISMAPOSTGRESRENDER

Technical Audit Procedure

rpc_security_audit.sql

Terminal|rpc_security_audit.sql

-- List all functions in the public schema and their security setting.

1SELECT
2 p.proname as function_name,
3 p.prosecdef as is_security_definer
4FROM pg_proc p
5JOIN pg_namespace n ON n.oid = p.pronamespace
6WHERE n.nspname = 'public';

Market Comparison

Why industry leaders choose DBX Deterministic Audits

FeatureDBX EngineManual AuditLegacy Scanners
Deterministic Path Analysis
Zero-Credential Architecture
Real-time Attack Path Graph
Automatic RLS Validation
Instant Compliance Proof
Copy-Paste Remediation

Technical Deep Dive

Remote Procedure Calls (RPC) in Supabase allow you to execute server-side logic directly from the client. However, because they run inside the database, they have the potential to bypass RLS if not implemented correctly. DBX audits your public schema functions, checking their security settings, input validation, and internal query logic to ensure they don't accidentally act as a backdoor into your protected data.

API security verification
Function logic validation
Backdoor detection
Input sanitization audit

Primary Vulnerability Vectors

  • 01
    Unauthorized data modification
  • 02
    Data exfiltration via RPC
  • 03
    Privilege escalation through functions

Audit Checklist

Verify all public RPC functions have security settings
Scan for SECURITY DEFINER on high-risk RPCs
Check for SQL injection in dynamic function logic
Validate that RPCs enforce tenant-id filtering
Audit function execution grants for the 'anon' role

How it works

High-integrity schema introspection

Introspect

Run a read-only script to extract your database catalog. No data ever leaves your machine.

Simulate

Our engine executes billion-path simulations to find logical RLS bypasses.

Remediate

Receive copy-paste SQL fixes for every high-risk vulnerability discovered.

Ready to secure your Supabase instance?

It takes less than 60 seconds to get a complete security posture analysis. No signup, no credit card, no risk.

Launch Deterministic Audit