mirror of
https://github.com/supabase/supabase.git
synced 2026-10-08 02:45:07 +03:00
docs(security): add GDPR, ISO 27001, and DDoS coverage to security guide
The /docs/guides/security landing page and regions guide had no mention of GDPR, ISO 27001, or DDoS protection despite Supabase covering these in one place or another. Adds a dedicated GDPR compliance guide (data residency + DPA), quick-win ISO 27001 and DDoS paragraphs to the landing page, and a data residency section to the regions guide. Closes DOCS-354.
This commit is contained in:
1 parent
4c8ed105d2
commit
2d7cbb5663
4 files changed
+26
No files matched your search
@@ -2616,6 +2616,7 @@ export const security: NavMenuConstant = {
|
||||
items: [
|
||||
{ name: 'SOC 2', url: '/guides/security/soc-2-compliance' },
|
||||
{ name: 'HIPAA', url: '/guides/security/hipaa-compliance' },
|
||||
{ name: 'GDPR', url: '/guides/security/gdpr-compliance' },
|
||||
],
|
||||
},
|
||||
{
|
||||
|
||||
@@ -4,6 +4,10 @@ title: Available regions
|
||||
|
||||
Each Supabase project is deployed to one primary region. Choose the location closest to your users for the best performance.
|
||||
|
||||
## Data residency
|
||||
|
||||
The region you choose also determines where your data is stored. If you have regulatory requirements — for example, GDPR — that require your data to stay within a specific jurisdiction, choose a [specific region](#specific-regions) rather than a general region grouping. General regions deploy to _an_ available AWS region within that broader area, which may not match a specific jurisdiction (for example, the "Europe" general region includes London and Zurich, which are not EU member states).
|
||||
|
||||
## General regions
|
||||
|
||||
For most projects, we recommend choosing a general region. Supabase will deploy your project to an available AWS region within that area based on current infrastructure capacity.
|
||||
|
||||
@@ -15,12 +15,18 @@ The [SOC 2 Compliance Guide](/docs/guides/security/soc-2-compliance) explains Su
|
||||
|
||||
The [HIPAA Compliance Guide](/docs/guides/security/hipaa-compliance) explains Supabase's HIPAA responsibilities. Additional [security and compliance controls](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) for projects that deal with electronic Protected Health Information (ePHI) and require HIPAA compliance are available through the HIPAA add-on.
|
||||
|
||||
Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized standard for information security management systems (ISMS), confirming that we maintain rigorous controls to protect customer data. Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
|
||||
|
||||
Supabase supports GDPR-compliant deployments, including EU-region hosting for data residency and a Data Processing Agreement (DPA) for customers who need one. The [GDPR compliance guide](/docs/guides/security/gdpr-compliance) explains this in more detail.
|
||||
|
||||
## Platform configuration
|
||||
|
||||
As a hosted platform, Supabase provides additional security controls to further enhance the security posture depending on organizations' own requirements or obligations.
|
||||
|
||||
These can be found under the [dedicated security page](/dashboard/org/_/security) under organization settings. And are described in greater detail [here](/docs/guides/security/platform-security).
|
||||
|
||||
In addition to protection at the CDN level via Cloudflare, Supabase employs fail2ban to block malicious IP addresses at the infrastructure layer, protecting the platform against Distributed Denial of Service (DDoS) attacks.
|
||||
|
||||
## Product configuration
|
||||
|
||||
Each product offered by Supabase comes with customizable security controls and these security controls help ensure that applications built on Supabase are secure, compliant, and resilient against various threats.
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
id: 'gdpr-compliance'
|
||||
title: 'GDPR compliance and Supabase'
|
||||
description: 'How Supabase supports GDPR-compliant deployments, including data residency and the Data Processing Agreement (DPA).'
|
||||
---
|
||||
|
||||
Supabase supports building GDPR-compliant applications. Building a compliant application is a [shared responsibility](/docs/guides/deployment/shared-responsibility-model): Supabase secures the underlying infrastructure, while you're responsible for your application's data processing activities, consent flows, and access controls.
|
||||
|
||||
## Data residency
|
||||
|
||||
Each Supabase project is deployed to a single primary region, and your project's primary Postgres database, Auth service, and Storage objects are hosted in that region. Choosing a [specific region](/docs/guides/platform/regions#specific-regions) within the EU pins your data to that exact AWS region. Note that the "Europe" general region grouping also includes London (UK) and Zurich (Switzerland) — both have GDPR-adequacy data protection regimes, but neither is an EU member state. If your compliance requirements call for data to stay within the EU specifically, choose a specific EU region rather than the general Europe grouping. See [available regions](/docs/guides/platform/regions) for the full list.
|
||||
|
||||
## Data processing agreement (DPA)
|
||||
|
||||
If you need a formal data processing contract under GDPR, Supabase provides a Data Processing Agreement (DPA). [Request or view the DPA](/legal/dpa).
|
||||
Reference in new issue
Block a user