Security/technical review
Budget: -
HOURLY / PART_TIME
⭐ 0.00 (0)
Canada
postgresql, next.js, react-js, database-design, api-integration, typescript, node.js, database-architecture, postgis, software-architecture, database-security, information-security
Qualifiche preferite
- Esperienza: Intermedio
We’re looking for an experienced **Supabase/Postgres security reviewer** to independently assess a production-bound AI application before we apply its database/runtime changes to production.
The application is a personalized AI advisor. A substantial architecture and security-remediation program has already been completed. We are **not looking for someone to take over or rebuild the application**. We need an independent expert to review the frozen implementation and tell us what is safe, what is not, and what—if anything—must be corrected before production.
The review will include:
* Supabase/Postgres architecture and migrations
* Row Level Security and cross-user isolation
* RPC/function authorization
* service-role and privileged-access boundaries
* identity, ownership and authorization enforcement
* migration ordering, rollback and recovery
* test coverage and missing adversarial cases
* production-readiness and security risks
We will provide a structured reviewer package with exact Git commits, architecture/security documentation, migrations, test evidence and known risk items.
**Expected deliverable:** an independent written review with findings ranked by severity, file/line references where applicable, clear reasoning, missing-test recommendations, and the smallest practical remediation for each finding. We also want a clear conclusion on whether the reviewed database/security package is safe to progress toward production.
Experience reviewing existing Supabase applications—especially RLS, PostgreSQL security and multi-tenant/user isolation—is important.
Experience with OpenAI/Anthropic integrations is a plus. We also have a separate controlled AI-testing path and may ask the reviewer to assess the technical privacy/security boundary around API keys, data sent to AI providers, local evidence storage, logging and retention.
We value careful, evidence-based review, clear communication and pragmatic recommendations. We are happy to work asynchronously through GitHub and written documentation.
**Most importantly: this is an independent review/audit engagement, not an open-ended development or rewrite project.**
Apri su Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Accedi