You rest. We take the nightshift.
We check one thing in multi-tenant apps: whether one customer's account can reach another customer's data.
For multi-tenant web apps, any stack, often built fast on Supabase or Lovable. With your written permission and test accounts you provide, we test from the outside and show you the proof.
Request a free first scanRead-only by default. Consent-first. No code access needed.
The problem
Most testing happens as a single user, so everything looks right. The bug only appears across accounts: user A opens a record, changes the ID in the URL or the request, and gets user B's data. The cause is usually small: a missing access rule, a query scoped to the wrong field, an ID that isn't checked. It doesn't throw an error and it doesn't show up in a demo. It shows up when a customer sees someone else's invoice.
We test one thing, properly: whether one customer's account can reach another customer's data. That covers broken access control, IDs that aren't checked, and missing or misconfigured row-level access rules (RLS).
We don't test for every kind of bug, and we don't promise to find every issue. We don't need your source code. We don't change or delete your data.
How it works
Nothing starts without your written OK.
Send us your written OK and logins for test accounts you've set up. We never create accounts.
We reach your app the way a real user does. No source code, nothing to install. By default we only read; deeper tests are opt-in.
Every finding is reproduced before we report it, with proof and a fix direction. One free re-check after you fix anything we find.
Your data
We show that a leak exists, never what's in it.
Who it's for
It's a common gap in apps built fast on Supabase or Lovable.
Your app works perfectly when you're the only one logged in. Find out whether one customer's account can reach another customer's data before a customer does.
You build fast, for many clients, on shared multi-tenant stacks. Find the issue in a scan, not in an angry email from your client's customer.
FAQ
We test only with the app owner's written permission, and only with test accounts they provide. The default test only reads. We don't change or delete data.
No. We test from the outside, the way a real user reaches the app. Nothing to install, no repo to share.
Every finding is reproduced before it goes in the report, and each one comes with the proof.
No, and we don't promise to. We show you, reproducibly, where your app leaks data between accounts.
Your first scan is free: a couple of test accounts you provide, read-only, and one free re-check after you fix anything we find.
Request a free first scanPlease don't send passwords in your first message.