DefenceCore

DefenceCore

Continuously watches your Supabase project's logs for security problems and explains them in plain language, instead of requiring you to hire a security engineer or learn to read raw audit logs.

🔗 Visit DefenceCore
📁 Security & Privacy🗣️ English📅 August 22, 2026

Description

Supabase gives you auth, database, storage and edge functions out of the box, but it doesn't watch those services for security misconfigurations on its own — a misconfigured Row Level Security policy or an exposed storage bucket can sit unnoticed for months. DefenceCore is built specifically for that gap: it continuously monitors logs across auth, APIs, databases, storage and edge functions on a Supabase project and surfaces findings in plain language rather than raw log dumps.

Every alert comes with evidence (the actual log snippet that triggered it) and an AI-ready fix recommendation formatted so a coding agent like Claude or Cursor can act on it directly. Setup is a 2-minute OAuth connection with read-only access — it explicitly cannot modify your database. There's also a free standalone scanner that checks RLS policies, storage rules and metadata in about 30 seconds without touching any actual data. The main monitoring service costs $29/month per Supabase project with a 7-day trial, and works even on Supabase's free tier.

💬 Our review

The short version: DefenceCore fills a specific, real gap — nobody is watching your Supabase logs for security issues by default — and the read-only, AI-ready-fix design is a smart fit for how small teams actually operate today, but it's narrowly scoped to Supabase only and unproven at scale.

The generic alternative is a full SIEM tool or manually reviewing Supabase's dashboard logs yourself, both of which are either expensive/overkill for a small project or realistically never happen. At $29/month per project, DefenceCore is cheap compared to a SIEM and far more likely to actually get used because it's purpose-built rather than general-purpose. The free scanner alone is worth running once regardless of whether you subscribe, since it costs nothing and catches common RLS misconfigurations. The obvious limitation: if you're not on Supabase, none of this applies, and if you outgrow single-project pricing across dozens of projects, costs add up fast.

💰 Pricing

Subscription + free tool$29/mo per Supabase project, 7-day trial. Free standalone scanner, no cost, read-only OAuth.
Free scanner $0Monitoring $29/mo per project

📊 Global score

45Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile75/100Bien

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Abonnement + outil gratuit

Service principal : 29 $/mois par projet Supabase, essai 7 jours. Scanner gratuit : sans coût, accès OAuth lecture seule.

👥 Target audienceÉquipes dev construisant sur Supabase sans staff sécurité dédié
🗣️ Languagesen
🌍 Target countriesWorldwide
👍

Pros

Surveillance continue des logs auth/API/DB/storage/edge functions

Alertes en langage clair avec preuve (extrait de log)

Recommandations de correctifs prêtes pour agents de code IA

Scanner gratuit RLS/storage en ~30 secondes, lecture seule

👎

Cons

Spécifique à Supabase uniquement, aucune portabilité

29 $/mois par projet, coût qui s'additionne sur plusieurs projets

Produit jeune, pas de preuve de traction à grande échelle

Accès lecture seule = ne corrige rien automatiquement

❓ Frequently asked questions

What is DefenceCore in one sentence?
How much does it cost?
Can it modify my database?
How fast is the free scanner?
Does it work with coding agents?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?