Security at Supabase

Supabase is trusted by thousands of developers for building and deploying secure applications.

Compliance

SOC 2#

Supabase is SOC 2 Type 2 compliant. This is an important security policy when handling sensitive customer data.

Enterprise and Team customers can access our SOC 2 Type 2 report on the dashboard.

HIPAA#

Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our shared responsibility model.

Enterprise and Team customers can request to sign our BAA on the dashboard.

ISO 27001#

Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized standard for information security management systems (ISMS), confirming that we maintain rigorous controls to protect customer data.

Enterprise and Team customers can access our ISO 27001 certificate on the dashboard.

GDPR & European Compliance#

Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR.

See how Markprompt uses Supabase for GDPR-compliant deployments.

Data

Data Encryption#

All customer data is encrypted at rest with AES-256 and in transit via TLS.

Sensitive information like access tokens and keys are encrypted at the application level before they are stored in the database.

Data Residency#

When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific.

See the full list of available regions.

Backups#

All paid customer databases are backed up every day.

Point in Time Recovery allows restoring the database to any point in time. Customers from the Pro Plan have access to this feature as an add-on.

Data Processing Agreement#

A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. Request or view the DPA.

Configuration

Multi-factor Authentication#

Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.

Role-based access control#

Members of organizations in Supabase can be granted access to specific resources.

Read more about fine-grained access controls including Read-Only and Billing-Only access.

Vulnerability Management#

Supabase works with industry experts to conduct regular penetration tests.

In addition to internal security reviews, we use various tools to scan our code for vulnerabilities including GitHub, Vanta, and Snyk.

DDoS Protection#

Supabase combats Distributed Denial of Service attacks in several ways to mitigate resource abuse and prevent runaway bills.

In addition to protection at the CDN level via Cloudflare, we employ fail2ban to prevent brute force logins. Users can customize rate limits for critical API routes and set spend caps to prevent surprise bills.

Misc

Shared Responsibility#

Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls.

Read the shared responsibility model.

Payment processing#

Supabase uses Stripe to process payments and does not store personal credit card information for any of our customers.

Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.

Security Newsletter

Sign up for the Supabase Security Newsletter. Receive updates during security incidents.