
One Toggle From a Breach: How We Built Keelscan to Scan Code, Live Apps, and Supabase in One Grade
Deals stall in security review, and the odds are against a team that shipped fast. We built Keelscan to answer "is your app secure?" across the three surfaces a reviewer actually checks: your code, your running app, and your cloud data config. This post walks through the engineering: catching a Supabase RLS leak with only the public anon key, scanning any URL without building an SSRF weapon, and why we made the grade less harsh to keep it honest.








