DefenceCore
Continuously watches your Supabase project's logs for security problems and explains them in plain language, instead of requiring you to hire a security engineer or learn to read raw audit logs.
🔗 Visit DefenceCoreDescription
Supabase gives you auth, database, storage and edge functions out of the box, but it doesn't watch those services for security misconfigurations on its own — a misconfigured Row Level Security policy or an exposed storage bucket can sit unnoticed for months. DefenceCore is built specifically for that gap: it continuously monitors logs across auth, APIs, databases, storage and edge functions on a Supabase project and surfaces findings in plain language rather than raw log dumps.
Every alert comes with evidence (the actual log snippet that triggered it) and an AI-ready fix recommendation formatted so a coding agent like Claude or Cursor can act on it directly. Setup is a 2-minute OAuth connection with read-only access — it explicitly cannot modify your database. There's also a free standalone scanner that checks RLS policies, storage rules and metadata in about 30 seconds without touching any actual data. The main monitoring service costs $29/month per Supabase project with a 7-day trial, and works even on Supabase's free tier.
💬 Our review
The short version: DefenceCore fills a specific, real gap — nobody is watching your Supabase logs for security issues by default — and the read-only, AI-ready-fix design is a smart fit for how small teams actually operate today, but it's narrowly scoped to Supabase only and unproven at scale.
The generic alternative is a full SIEM tool or manually reviewing Supabase's dashboard logs yourself, both of which are either expensive/overkill for a small project or realistically never happen. At $29/month per project, DefenceCore is cheap compared to a SIEM and far more likely to actually get used because it's purpose-built rather than general-purpose. The free scanner alone is worth running once regardless of whether you subscribe, since it costs nothing and catches common RLS misconfigurations. The obvious limitation: if you're not on Supabase, none of this applies, and if you outgrow single-project pricing across dozens of projects, costs add up fast.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Service principal : 29 $/mois par projet Supabase, essai 7 jours. Scanner gratuit : sans coût, accès OAuth lecture seule.
Pros
Surveillance continue des logs auth/API/DB/storage/edge functions
Alertes en langage clair avec preuve (extrait de log)
Recommandations de correctifs prêtes pour agents de code IA
Scanner gratuit RLS/storage en ~30 secondes, lecture seule
Cons
Spécifique à Supabase uniquement, aucune portabilité
29 $/mois par projet, coût qui s'additionne sur plusieurs projets
Produit jeune, pas de preuve de traction à grande échelle
Accès lecture seule = ne corrige rien automatiquement