
I have 6+ years of production full-stack/backend experience working with PostgreSQL, Node.js, React, AWS, authentication/authorization, and multi-tenant SaaS architectures.
I’ve worked on production systems where tenant/workspace-level data isolation, access control, API authorization, database integrity, and security were critical. My approach to an audit is to trace authorization end-to-end, review database policies and queries, test cross-tenant access paths, inspect guest/public-link flows, and add targeted tests for the highest-risk scenarios.
While my strongest production experience is with PostgreSQL-based SaaS architectures rather than Supabase specifically, I’m comfortable working directly with PostgreSQL security concepts including Row Level Security, roles, policies, least-privilege access, transactions, indexes, and tenant-scoped data. I focus on producing a prioritized findings report with evidence and clear business impact rather than simply making a large set of code changes.
Relevant experience: Hikaflow, where I’ve worked on production AI/SaaS workflows and enterprise-facing systems involving authentication, data access, APIs, cloud infrastructure, and security considerations.

