Make sure a stranger can’t read your users’ data.
Your Firebase rules decide who can. Intellity loads them into the real Firebase engine, then attacks them like an anonymous visitor and a logged-in user, so you see exactly what they leave open, with the fix for each one.
New to this? Where do I find my rules?
rules_version = '2';) and paste them above. That is all Intellity needs. No keys, and no access to your project.Sign in to keep scanning.
Sign in with a free account to keep scanning as often as you like, and connect your live Firebase to check the rules you actually have deployed.
Continue scanning for free →Takes a few seconds, and scanning is free.
↓ a real scan of a deliberately vulnerable example app, not your rules
Three lines of loose rules just handed a stranger every user’s email, your payment data, and admin over everything. That is what a scan catches, before someone else does.
Now watch your real project, on every deploy.
Create a free account to connect your Firebase in a click and scan the rules you actually have deployed. Then turn on monitoring, and Intellity re-checks every deploy and emails you the moment one opens a new hole, so an exposure never sits there unnoticed.
Free to scan and connect. Monitoring is Pro, with a 14-day free trial and cancel anytime.
How it works, in four steps.
No magic, and no LLM opinion in the loop. Here is the whole thing, start to finish.
storage.rules
You paste your rules
Just the rules text you already have. No keys, no data, and no access to your live project.
We load them into the real engine
The actual Firebase rules engine, the same one Google runs in production, in a private sandbox.
We run every attack
Every request an attacker would try, as an outsider and as a logged-in user, against each path.
You get proof and the fix
Every hole it opened, the exact request that proves it, and the one rule change that closes it.
A security tool must never be the leak.
So Intellity is built to need almost nothing from you. Here is exactly what it touches, and what it never does.
Rules text only
You paste your rules. We never ask for a key, a token, or a connection to your live project.
An isolated sandbox
Every scan runs in a private, throwaway sandbox that is destroyed the moment it finishes.
Nothing sensitive kept
We keep only anonymised patterns to sharpen our checks. Never your project, and never a record.
No production impact
Writes and deletes are simulated inside the engine, never executed against anything real.
What Intellity does today, and what is next.
Right now it proves your Firestore and Storage rules, connects to your live project, and re-checks every deploy. That is one layer of one backend. We only claim what we can prove today, and we ship the rest continuously.
Live today
On the roadmap
Everything on the right ships into the same account you start today, and your monitoring keeps working while we build it. The earlier you get on, the more it compounds.
Start free →Questions, answered.
The things developers ask before they paste their rules in.
What does Intellity access?
Is it safe to paste my rules?
What does connecting my Firebase do?
What is continuous monitoring?
Why not just paste them into an LLM (Claude, ChatGPT, etc.)?
What does it cost?
What is coming next?
See what your rules actually allow.
Paste them and get proof, with the exact fixes, in seconds. No project access and no keys. Then create a free account to connect your Firebase and watch every deploy.
Scan my rules →Free to scan and connect. Create a free account →