Supabase RLS / Multi-Tenant Security Review
Worldwide
We need a security expert to review our legal SaaS application’s Supabase architecture and confirm multi-tenant isolation is working correctly. The work includes reviewing current RLS rules, identifying gaps, and recommending fixes. You will also assess how tenant data is separated and verify that users can only access their own tenant data. This is a scoped, fixed-price review focused on security validation, not full development or implementation. We run a live case management application for law firms, built on Supabase (Postgres + Auth + Storage). The app is multi-tenant — multiple independent law firms use the same system, and each firm's data must be completely isolated from every other firm's. How access will work: We will create a dedicated synthetic test firm inside our live system, seeded entirely with fake case data — no real client information will be involved. You'll get one admin login and one staff login scoped to that test firm only. You are testing whether that synthetic firm's account can reach any other (real) firm's data — this is the actual scenario we're worried about. Rules of engagement (will be formalized in a signed agreement before access is granted): No denial-of-service testing or anything that could take the production system down for active users. Read-only — no modifying or deleting data outside the synthetic test firm. If you find a way to access real firm data, stop immediately and report it privately with minimal detail (e.g. "table X, record Y") rather than continuing to explore or exfiltrating anything. NDA required before access is granted — happy to sign a mutual one, or use yours if it covers confidentiality of any data encountered. Deliverable: A written report listing findings (with severity), how to reproduce each one, and recommended fixes. A brief follow-up call to walk through findings is a plus but not required. Timeline: Looking to complete this within a week or so We need a focused, scoped security review, not a full-scale penetration test. Specifically: Row Level Security (RLS) review — confirm our RLS policies correctly enforce tenant isolation, and that there's no way for one firm's account to read, write, or enumerate another firm's data (cases, documents, users). Basic auth/API check — confirm role/permission checks happen server-side, JWT/session handling is sound, and no admin/service-role credentials are exposed to the client. Storage check — confirm uploaded case documents are only accessible to the firm that owns them (no public buckets, no guessable signed URLs across tenants).
- Less than 30 hrs/weekHourly
- < 1 monthDuration
- IntermediateExperience Level
- Remote Job
- One-time projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:yesterday
- Interviewing:6
- Invites sent:0
- Unanswered invites:0
About the client
- USABoston11:19 PM
- $1.8K total spent2 hires, 0 active
- 70 hours
- LegalIndividual client
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by