Help prove the tenant-isolation workflow on a real SaaS repository.
BoundaryCI is selecting five multi-tenant SaaS teams for a no-cost, founder-led install and baseline review. The goal is to measure setup friction, false positives, remediation usefulness, and whether the check earns a place in the required pull-request workflow.
Who is a strong fit
The useful design partner is close enough to production that tenant-isolation mistakes matter and can evaluate BoundaryCI against real migration history. Supabase is the initial focus; PostgreSQL teams with SQL migrations and shared customer tables are also relevant.
- A multi-tenant SaaS product serving external customers or approaching a committed launch
- Supabase or PostgreSQL authorization expressed in version-controlled SQL migrations
- A team willing to run BoundaryCI in report-only mode before deciding whether to require it
- An engineer who can join one setup session and one follow-up conversation
What the pilot includes
BoundaryCI will help install the current GitHub Action, review initial deterministic findings, create a baseline only after the findings are understood, and evaluate the managed AI layer when the team explicitly consents to that data flow.
- Founder-led repository setup and workflow configuration
- Initial finding and baseline review
- Direct handling of false positives and unclear remediation
- A written summary of setup time, finding quality, and next workflow improvements
What BoundaryCI asks in return
Design partners provide candid evidence rather than a testimonial obligation. The essential signal is whether the scanner finds useful issues, avoids merge noise, and becomes trustworthy enough to remain in the pull-request path.
- Permission to measure setup time and aggregate finding outcomes
- Specific feedback on false positives, missed risks, and remediation clarity
- A decision after the pilot: remove it, keep it report-only, or make it a required check
- Optional permission for an attributed case study only after separate written approval
Apply without disclosing sensitive information
The application opens a public GitHub issue. Share only your stack, product stage, approximate repository count, and a non-confidential description of the current review workflow. Do not post repository names, customer information, credentials, migrations, or suspected vulnerabilities.
Qualified teams can coordinate private repository details outside the public issue after the initial fit check.