Security audits for Base44 apps.

In a Base44 app, every entity has access rules deciding which users can read and write its records. Left permissive, an entity quietly hands any signed-in user other users' data. We test what your app actually returns, and hand you the fixes.

Get a quote

Why it matters

Base44 gives every app a solid foundation: hosted infrastructure, built-in authentication, an API for each entity. What no platform can do is decide who should see what inside your app, because that depends entirely on your data model. An entity holding orders, messages or documents that is readable by any authenticated user works perfectly in every demo, and shares every customer's records with every other customer at the same time. The flaw lives in the relationship between two accounts, so an owner testing alone never sees it. That is the class of issue we go looking for, with two accounts and the API in front of us.

What you get.

Entity access review

Every entity's read and write rules checked against who should actually see its records, with the correct rule spelled out for each one that is too permissive.

Two-account access test

We sign in as one user and try to reach another user's records through the app and the entity API. This is the check that finds cross-customer exposure, and it cannot be done from one account.

API exposure test

We read the raw responses behind your pages and features, anonymous and signed in, and flag the fields that ship but never display: internal IDs, emails and personal data a visible page quietly carries.

Backend functions and integrations

Functions callable without proper checks, integration keys that ended up readable in the client, and anything privileged reachable from the browser.

Authentication review

How sign-up, roles and invitations are configured, and whether any admin surface is reachable by an ordinary account.

Prioritised report and free re-review

Every finding rated by severity with a concrete fix, and a free re-test of the same surface once you have applied them.

How it works.

  1. 01

    Access

    You share the app's URL and a short walkthrough of what it does and who should see what. Two test accounts help; we can usually create our own.

  2. 02

    Test

    We probe the live app and its API from outside with real accounts, then review the entity rules with you, by hand.

  3. 03

    Report

    You get a clear, prioritised write-up within days, plus a call to walk through it and the correct rule for each entity.

  4. 04

    Re-review

    After you apply the fixes, we verify the exposed entities and endpoints are actually closed.

Common questions.

Isn't Base44 secure out of the box?
The platform layer is not the problem; hosting and authentication are handled for you. What we audit is the app layer: the access rules on your entities and what your specific app returns, which are decisions each app makes for itself. Nearly every finding on a Base44 audit is app configuration, not a platform flaw.
Do you actually know the platform?
Yes. Thunkle is a listed Base44 partner, and we have audited, fixed and extended Base44 apps for real businesses. We know where the platform ends and your configuration begins, which is exactly the line an audit has to walk.
What do you check?
Access rules on every entity, cross-account access with two real accounts, the raw data behind public and signed-in features, backend functions and integration keys, and the authentication and role setup. Every finding comes with a severity and a fix.
Can you fix the issues, not just find them?
Yes. We can apply the fixes in your app directly or hand you a clear prioritised list. And if your app has outgrown what it started as, we can talk about a graduation path where you own the code, without disrupting what already works.
How much does a Base44 security audit cost?
It is scoped to a fixed quote up front, with no hourly meter, and typically starts around $750 depending on the size of the app. You will know the price before we begin.

Related services.

Let's build something real.

Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.

Get a quote