diff --git a/apps/docs/content/guides/platform/shared-responsibility-model.mdx b/apps/docs/content/guides/platform/shared-responsibility-model.mdx index 27ff9b2cc08..aab305241e4 100644 --- a/apps/docs/content/guides/platform/shared-responsibility-model.mdx +++ b/apps/docs/content/guides/platform/shared-responsibility-model.mdx @@ -6,6 +6,19 @@ description: 'Running databases is a shared responsibility between you and Supab Running databases is a shared responsibility between you and Supabase. There are some things that we can take care of for you, and some things that you are responsible for. This is by design: we want to give you the freedom to use your database however you want. While we _could_ put many more restrictions in place to ensure that you can’t do anything wrong, you will eventually find those restrictions prohibitive. +Shared responsibility model + +To summarize, you are always responsible for: + +- Your Supabase account +- Access management (Supabase account, database, tables, etc) +- Data +- Applying security controls + Generally, we aim to reduce your burden of managing infrastructure and knowing about Postgres internals, minimizing configuration as much as we can. Here are a few things that you should know: ## You share the security responsibility @@ -16,6 +29,10 @@ If you have an inexperienced member on your team, then you probably shouldn’t You are also responsible for ensuring that tables with sensitive data have the right level of access. You are also responsible for managing your database secrets and API keys, storing them safely in an encrypted store. +Supabase provides controls for [securing your data](/docs/guides/database/secure-data), and it is recommended that you always apply [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS). + +We will also provide you with security alerts through [Security Advisor](https://supabase.com/dashboard/project/_/database/security-advisor) and applying the recommendations are your responsibility. + ## You decide your own workflow There are _many_ ways to work with Supabase. @@ -44,6 +61,10 @@ You are responsible for using best-practices to optimize and manage your databas You are responsible of provisioning enough compute to run the workload that your application requires. The Supabase Dashboard provides [observability tooling](https://supabase.com/dashboard/project/_/reports/database) to help with this. +## Before going to production + +We recommend reviewing and applying the recommendations offered in our [Production Checklist](/docs/guides/platform/going-into-prod). This checklist covers the responsibilities discussed here and a few additional general production readiness best practices. + ## Managing healthcare data You can use Supabase to store and process Protected Health Information (PHI). You are responsible for the following diff --git a/apps/docs/public/img/platform/shared-responsibility-model.png b/apps/docs/public/img/platform/shared-responsibility-model.png new file mode 100644 index 00000000000..938aaa8af2f Binary files /dev/null and b/apps/docs/public/img/platform/shared-responsibility-model.png differ