You rest. We take the nightshift.
Can one of your users read another's data?
For multi-tenant apps, often built fast on Supabase or Lovable.
- Written authorisation first
- Designed to minimise impact
- Free scan + one free re-check
- Findings sent only to you
A quiet bug that only appears across accounts
How it works
- 01
You authorise
- 02
We test with two labelled test accounts
- 03
Private report + one free re-check
What we don't do
- We don't intentionally read, copy or keep your customers' real data. Proof is limited to row counts, record IDs, tenant IDs and column names.
- We don't test without your written authorisation.
- We don't run load or stress tests.
- We don't intentionally invite users, message anyone, touch billing or post publicly.
- Findings are confidential and sent only to you.
Questions
How is testing authorised?
Only after a founder, director or named CTO/security lead replies "I confirm" to our scope email, which sets the dates, request rate and anything off-limits. Full rules: scan terms.
What do you add to our app?
Two labelled test accounts and a few test records labelled NIGHTSHIFT TEST inside them. We delete them within 7 days of the report; if your app can't (or only soft-deletes), we send you the account IDs and removal is yours from then.
What if our signup is closed or paid?
Then you give us test logins instead. They're used only for the scan and deleted on our side when it's done; we recommend you disable or rotate them afterward.
Do you need our source code?
No. We test from the outside, the way a real user reaches the app. No installs, no repo to share.
What about false positives?
Every finding is reproduced before it goes in the report, and each one comes with the proof.
Do you find every bug?
No, and we don't promise to. We show you, reproducibly, where your app leaks data between accounts.
Find out whether your users' data stays theirs.
Your first scan is free, with one free re-check after your fix.
Request a free scanPlease don't send passwords in your first message.