Security audits for Base44 apps.
In a Base44 app, every entity has access rules deciding which users can read and write its records. Left permissive, an entity quietly hands any signed-in user other users' data. We test what your app actually returns, and hand you the fixes.
Why it matters
Base44 provides hosting, authentication, security scans and entity permissions. The application still needs those permissions to match its business rules. Customers, office staff and administrators may legitimately need different access to the same records and fields. We review that model with you and test the agreed backend paths, including cases a normal single-account walkthrough does not exercise.
What you get.
Entity and field access review
We review the scoped entities' create, read, update and delete permissions, plus access to sensitive fields. Rules are checked against intended ownership, sharing and staff roles, with remediation guidance for validated gaps.
Two-account access test
We use dedicated accounts and synthetic records to check allowed access and cross-account attempts that should fail. Relevant staff, administrator and revoked-access scenarios are included in the agreed scope.
API exposure test
We inspect agreed public and authenticated responses for fields that should not be delivered to the caller. Visible identifiers are assessed in context, not automatically reported as leaks.
Backend functions and integrations
We check authorization around privileged functions and integrations, including caller identity, permitted records and side effects. Public endpoints are tested against their intended purpose rather than assumed to be flaws.
Authentication review
How sign-up, roles and invitations are configured, and whether any admin surface is reachable by an ordinary account.
Prioritised report and free re-review
Every finding rated by severity with a concrete fix, and a free re-test of the same surface once you have applied them.
How it works.
- 01
Access
We agree scope, environments and permitted actions, then arrange the necessary source/configuration access and dedicated accounts. Secrets and customer exports do not belong in a quote request.
- 02
Test
We review the agreed entity rules and backend logic alongside authorized application tests. Mutation and integration checks use synthetic data and an agreed safe environment.
- 03
Report
You get a clear, prioritised write-up within days, plus a call to walk through it and the correct rule for each entity.
- 04
Re-review
After you apply the fixes, we verify the exposed entities and endpoints are actually closed.
Common questions.
- Isn't Base44 secure out of the box?
- Base44 supplies security controls and scanning, but the platform name alone cannot establish whether a particular app meets its requirements. We review the scoped application permissions and workflows without assuming either that the platform is vulnerable or that every configuration is safe.
- Do you actually know the platform?
- Yes. Thunkle is a listed Base44 partner, and we have audited, fixed and extended Base44 apps for real businesses. We know where the platform ends and your configuration begins, which is exactly the line an audit has to walk.
- What do you check?
- The agreed entity and field permissions, cross-account and role boundaries, public data responses, backend functions, credentials and critical integrations. The report includes evidence, severity, remediation guidance and explicit scope limitations.
- Can you fix the issues, not just find them?
- Yes. Fix implementation can be scoped separately, or your team can apply the guidance and use the free re-review of the agreed fixes. Migration is considered separately when requirements justify it; it is not an automatic security fix.
- How much does a Base44 security audit cost?
- It is scoped to a fixed quote up front, with no hourly meter, and typically starts around $750 depending on the size of the app. You will know the price before we begin.
Related services and guides.
Know what needs fixing before you ship.
Get a scoped developer review, evidence-backed findings and remediation guidance, with a free re-review of agreed fixes. Fix implementation is quoted separately.
