Many AI-built apps talk to a hosted backend straight from the browser, using a public client key. That is safe only when the database itself refuses what the user is not allowed to see. The feature that does this is row level security. Left off, the public key reads everything.
The check that matters
- Find the public client key and project address in your served JavaScript.
- Signed out, use them to read each table that holds user data.
- Any rows returned is a critical finding. Empty results or a permission error is a pass.
Fix it
List every table in the database. For each table holding user data, enable row level security and add policies so a signed-in user can read and write only their own rows, and a signed-out request can read nothing. Put the changes in a migration. Do not use the service role key anywhere that runs in the browser. Show me the final policy for each table.
Keep it locked
- Every new table starts with row level security on. Add that line to the instructions your coding tool reads.
- The service role key bypasses every policy. It belongs on the server only.
- Run the signed-out read again after every schema change.