Nightshift

You rest. We take the nightshift.

Can one of your users read another's data?

We check one thing in multi-tenant apps: whether one customer's account can reach another customer's data.

For multi-tenant web apps, any stack, often built fast on Supabase or Lovable. With your written permission and test accounts you provide, we test from the outside and show you the proof.

Request a free first scan

Read-only by default. Consent-first. No code access needed.

The problem

A quiet bug that only appears across accounts

Most testing happens as a single user, so everything looks right. The bug only appears across accounts: user A opens a record, changes the ID in the URL or the request, and gets user B's data. The cause is usually small: a missing access rule, a query scoped to the wrong field, an ID that isn't checked. It doesn't throw an error and it doesn't show up in a demo. It shows up when a customer sees someone else's invoice.

What we do

We test one thing, properly: whether one customer's account can reach another customer's data. That covers broken access control, IDs that aren't checked, and missing or misconfigured row-level access rules (RLS).

What we don't

We don't test for every kind of bug, and we don't promise to find every issue. We don't need your source code. We don't change or delete your data.

How it works

Three steps, and you stay in control

Nothing starts without your written OK.

1

You give permission

Send us your written OK and logins for test accounts you've set up. We never create accounts.

2

We test from the outside

We reach your app the way a real user does. No source code, nothing to install. By default we only read; deeper tests are opt-in.

3

You get the proof

Every finding is reproduced before we report it, with proof and a fix direction. One free re-check after you fix anything we find.

Your data

What we never do

We show that a leak exists, never what's in it.

Who it's for

Teams shipping multi-tenant apps fast

It's a common gap in apps built fast on Supabase or Lovable.

Founders

Your app works perfectly when you're the only one logged in. Find out whether one customer's account can reach another customer's data before a customer does.

Agencies

You build fast, for many clients, on shared multi-tenant stacks. Find the issue in a scan, not in an angry email from your client's customer.

FAQ

Questions

How do you keep this safe and authorized?

We test only with the app owner's written permission, and only with test accounts they provide. The default test only reads. We don't change or delete data.

Do you need our source code?

No. We test from the outside, the way a real user reaches the app. Nothing to install, no repo to share.

What about false positives?

Every finding is reproduced before it goes in the report, and each one comes with the proof.

Do you find every bug?

No, and we don't promise to. We show you, reproducibly, where your app leaks data between accounts.

Find out whether your users' data stays theirs.

Your first scan is free: a couple of test accounts you provide, read-only, and one free re-check after you fix anything we find.

Request a free first scan

Please don't send passwords in your first message.