No sign-up11,173 open-source and SaaS tools, with GitHub stats refreshed every day.

sentris

SaaS

Security scanner for Supabase and AI-written apps that reads your repo and live bundle for missing RLS, leaked service_role keys and public buckets.

sentris.dev
sentris homepage screenshot

About sentris

Sentris is a security scanner for apps built on Supabase and with AI-generated code. It reads your repository (migrations, config, route handlers), plus the live client bundle and response headers, and reports exposures such as service_role keys in the bundle, tables without row-level security, policies using true, public storage buckets and routes with no auth check. Each finding names the exact file and line and includes SQL to fix it.

The site states that no AI finding reaches the user unless it can quote the file character for character, that the scanner never exploits what it finds, and that it publishes a false-positive rate. A free scan needs no login; a URL scan covers exposed secrets and security headers, while connecting GitHub with read-only access (nothing is cloned) scans the code. Other checks listed include Stripe and AI-provider keys, committed .env files, unverified JWTs, secrets shipped as NEXT_PUBLIC variables, MD5 password hashing, cookies without HttpOnly, SQL built by concatenation and dependencies with known CVEs. It can be driven from Claude Code, Cursor and Windsurf over MCP. Scanning is free, and findings and fixes start from $19 a month.

Key features

  • Repo-level scan of migrations and route handlers
  • Detection of missing RLS and leaked keys
  • Exact file and line with SQL fix
  • Free scan with no login
  • Read-only GitHub connection
  • MCP access from Claude Code and Cursor

Good fit for

  • Auditing a Supabase app before launch
  • Checking AI-written code for exposed secrets
Tags
security-scanner
supabase
rls
secrets-detection
ai-generated-code
mcp

sentris: questions and answers

What is sentris used for?
sentris is a security scanner for Supabase and AI-written apps that reads your repo and live bundle for missing RLS, leaked service_role keys and public buckets. It is a good fit for auditing a Supabase app before launch and checking AI-written code for exposed secrets.
How much does sentris cost?
Paid plans for sentris start at $19 per month, and there is no free plan.
Is sentris open source?
No. sentris is proprietary (closed-source) software and can't be self-hosted. In the Marketing & SEO category, open-source options include OpenSEO, Dub and YOURLS.
What are some alternatives to sentris?
sentris competes with Outgrow, involve.me and Interact Quiz Maker.

Open-source alternatives to sentris

See all

SaaS alternatives to sentris

See all