All posts
2 min readby Romiel Inolino

Around 16,000 Supabase databases found exposing personal data: a checklist for vibe coded client apps

Supabasesecurityvibe codingdatabasesAI apps

Fast AI built apps are shipping with their databases wide open, and the fix is mostly configuration.

What happened

TechCrunch reported on September 25 that security firm UpGuard found around 16,000 databases hosted on Supabase with some degree of personal data exposed to the public web. The exposed data included names, addresses, phone numbers and user passwords, with a smaller number of passwords and authentication tokens. Examples included license plates from a U.S. valet service and contact details from an immigration and relocation service.

TechCrunch notes that Supabase has grown on the back of developers hosting vibe coded apps, and that AI generated code can contain security flaws or need configuration the developer does not know about. Supabase's CISO Bil Harmer said projects are "secure by default" and described security as a shared responsibility: "customers control how their own projects are configured."

Supabase's own documentation is direct about the key setting. A table in an exposed schema without Row Level Security is readable and writable by any role with a grant on it. The docs say to enable RLS on every table in an exposed schema, and note that adding policies does not remove existing grants.

My take

Many small businesses now have an internal tool, portal or lead form someone built in a weekend with an AI assistant. Those apps often store exactly the data in this report: names, phone numbers, addresses.

Before any Supabase backed app I build goes live, I run through this:

  1. RLS enabled on every table in an exposed schema, with explicit policies.
  2. Grants reviewed, so the anonymous role only has the operations it truly needs.
  3. The service role key kept server side only, never in the browser or a public repo.
  4. A test with the public anon key to confirm what a stranger can actually read.
  5. Personal data kept in the fewest tables possible.

AI can write the app. It will not reliably configure your access rules unless someone asks the right questions.

More posts