Sentris scans your Supabase repo, not just the live URL — the two are not the same
thing. Missing RLS policies, service_role keys hardcoded in source, public storage
buckets, routes that take an id and never check who is asking, security definer
functions anyone can call. Every finding comes with masked evidence — the exact line,
row counts, status codes — and a copy-paste fix. I scanned 2,144 public vibe-coded
repos while building it: 40.6% had a critical exposure. Free scan, no login.