The context
An EdTech platform in academic thesis stage, preparing for its first beta with 50 real users. Modern stack, well-designed product and committed technical team. Days before launch.
What they asked for
A technical review before opening the platform to real users. Not an exhaustive analysis: just the confidence that nothing critical existed before exposing student data.
What we found
We found a critical vulnerability in the data security layer, identified through gray-box testing and exploited in a controlled way with a direct script against the database. The Row Level Security (RLS) policy in Supabase looked correct in a superficial review, but under certain authenticated conditions it was possible to access records from other users, including personal information and academic progress.
What we delivered
Attack vector identification
Demonstration of the exploit in a test environment and a full analysis of the defect in the security policy.
Fix recommendation
Correct RLS policy, schema validation and review of similar risk points across the system.
Verification and hardening
Additional recommendations to strengthen the platform before opening to real users.
The result
The beta launched without incidents. The initial 50 users operated on a platform with the correct security policy from day one. There was no data exposure and no need to disclose a breach.
Services involved
- Technical security audit
- RLS policy analysis in Supabase
- Data architecture review
Sector
EdTech · Learning platforms · Startups in pre-launch stage