diff --git a/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts b/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
index 169ee9b25c1..a0e9c1bacfd 100644
--- a/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
+++ b/apps/docs/components/Navigation/NavigationMenu/NavigationMenu.constants.ts
@@ -2088,6 +2088,7 @@ export const security: NavMenuConstant = {
name: 'Product security',
url: undefined,
items: [
+ { name: 'Platform configuration', url: '/guides/security/platform-security' },
{ name: 'Product configuration', url: '/guides/security/product-security' },
{ name: 'Security testing', url: '/guides/security/security-testing' },
],
@@ -2170,12 +2171,8 @@ export const platform: NavMenuConstant = {
url: '/guides/platform/multi-factor-authentication',
items: [
{
- name: 'Enable MFA',
- url: '/guides/platform/multi-factor-authentication',
- },
- {
- name: 'Require MFA for organization members',
- url: '/guides/platform/org-mfa-enforcement',
+ name: 'Enforce MFA on organization',
+ url: '/guides/platform/mfa/org-mfa-enforcement',
},
],
},
diff --git a/apps/docs/content/guides/platform/org-mfa-enforcement.mdx b/apps/docs/content/guides/platform/mfa/org-mfa-enforcement.mdx
similarity index 93%
rename from apps/docs/content/guides/platform/org-mfa-enforcement.mdx
rename to apps/docs/content/guides/platform/mfa/org-mfa-enforcement.mdx
index 6f5a3b95bc9..3fd7a1ff4ec 100644
--- a/apps/docs/content/guides/platform/org-mfa-enforcement.mdx
+++ b/apps/docs/content/guides/platform/mfa/org-mfa-enforcement.mdx
@@ -9,8 +9,6 @@ Supabase provides multi-factor authentication (MFA) enforcement on the organizat
MFA enforcement is only available on the [Pro, Team and Enterprise plans](https://supabase.com/pricing).
-This feature is currently in limited preview. If you would like to opt-in to try it, contact support.
-
## Manage MFA enforcement
diff --git a/apps/docs/content/guides/security.mdx b/apps/docs/content/guides/security.mdx
index 6d7e4cb7356..f798002bb9c 100644
--- a/apps/docs/content/guides/security.mdx
+++ b/apps/docs/content/guides/security.mdx
@@ -17,6 +17,12 @@ The [HIPAA Compliance Guide](/docs/guides/security/hipaa-compliance) explains Su
# Platform configuration
+As a hosted platform, Supabase provides additional security controls to further enhance the security posture depending on organizations' own requirements or obligations.
+
+These can be found under the [dedicated security page](https://supabase.com/dashboard/org/_/security) under organization settings. And are described in greater detail [here](/docs/guides/security/platform-security).
+
+# Product configuration
+
Each product offered by Supabase comes with customizable security controls and these security controls help ensure that applications built on Supabase are secure, compliant, and resilient against various threats.
The [security configuration guides](/docs/guides/security/product-security) provide detailed information for configuring individual products.
diff --git a/apps/docs/content/guides/security/platform-security.mdx b/apps/docs/content/guides/security/platform-security.mdx
new file mode 100644
index 00000000000..8fee881ff3f
--- /dev/null
+++ b/apps/docs/content/guides/security/platform-security.mdx
@@ -0,0 +1,66 @@
+---
+id: 'platform-security'
+title: 'Secure configuration of Supabase platform'
+description: 'Supabase provides a secure yet flexible platform. Here is how to adjust various security settings across the platform.'
+---
+
+The Supabase hosted platform provides a secure by default configuration. Some organizations may however require further security controls to meet their own security policies or compliance requirements.
+
+Access to additional security controls can be found under the [security tab](https://supabase.com/dashboard/org/_/security) for organizations.
+
+## Available controls
+
+
+
+Additional security controls are under active development. Any changes will be published here and
+in our [changelog](https://supabase.com/changelog).
+
+
+
+### Enforce multi-factor authentication (MFA)
+
+Organization owners can choose to enforce MFA for all team members.
+
+For configuration information, see [Enforce MFA on Organization](/docs/guides/platform/mfa/org-mfa-enforcement)
+
+### SSO for organizations
+
+Supabase offers single sign-on (SSO) as a login option to provide additional account security for your team. This allows company administrators to enforce the use of an identity provider when logging into Supabase.
+
+For configuration information, see [Enable SSO for Your Organization](/docs/guides/platform/sso).
+
+### Postgres SSL enforcement
+
+Supabase projects support connecting to the Postgres DB without SSL enforced to maximize client compatibility. For increased security, you can prevent clients from connecting if they're not using SSL.
+
+For configuration information, see [Postgres SSL Enforcement](/docs/guides/platform/ssl-enforcement)
+
+
+
+ Controlling this at the organization level is on our roadmap.
+
+
+
+### Network restrictions
+
+Each Supabase project comes with configurable restrictions on the IP ranges that are allowed to connect to Postgres and its pooler ("your database"). These restrictions are enforced before traffic reaches the database. If a connection is not restricted by IP, it still needs to authenticate successfully with valid database credentials.
+
+For configuration information, see [Network Restrictions](/docs/guides/platform/network-restrictions)
+
+
+
+ Controlling this at the organization level is on our roadmap.
+
+
+
+### PrivateLink
+
+PrivateLink provides enterprise-grade private network connectivity between your AWS VPC and your Supabase database using AWS VPC Lattice. This eliminates exposure to the public internet by creating a secure, private connection that keeps your database traffic within the AWS network backbone.
+
+For configuration information, see [PrivateLink](/docs/guides/platform/privatelink)
+
+
+
+PrivateLink is currently in alpha and available exclusively to Enterprise customers.
+
+
diff --git a/apps/docs/content/guides/security/product-security.mdx b/apps/docs/content/guides/security/product-security.mdx
index 006d5658374..2c46fe215b4 100644
--- a/apps/docs/content/guides/security/product-security.mdx
+++ b/apps/docs/content/guides/security/product-security.mdx
@@ -1,7 +1,7 @@
---
id: 'product-security'
title: 'Secure configuration of Supabase products'
-description: 'Supabase provides a secure yet flexible platform. Here is how to adjust various security settings across the platform.'
+description: 'Supabase provides a secure yet flexible set of products. Here is how to adjust various security settings across the various products.'
---
The Supabase [production checklist](/docs/guides/deployment/going-into-prod) provides detailed advice on preparing an app for production. While our [SOC 2](/docs/guides/security/soc-2-compliance) and [HIPAA](/docs/guides/security/hipaa-compliance) compliance documents outline the roles and responsibilities for building a secure and compliant app.
diff --git a/apps/studio/components/layouts/ProjectLayout/OrganizationSettingsLayout.tsx b/apps/studio/components/layouts/ProjectLayout/OrganizationSettingsLayout.tsx
index 5cb4130dce2..b52a30832ac 100644
--- a/apps/studio/components/layouts/ProjectLayout/OrganizationSettingsLayout.tsx
+++ b/apps/studio/components/layouts/ProjectLayout/OrganizationSettingsLayout.tsx
@@ -3,7 +3,6 @@ import { PropsWithChildren } from 'react'
import { useParams } from 'common'
import { useCurrentPath } from 'hooks/misc/useCurrentPath'
-import { useFlag } from 'hooks/ui/useFlag'
import { NavMenu, NavMenuItem } from 'ui'
import { ScaffoldContainerLegacy, ScaffoldTitle } from '../Scaffold'
@@ -13,9 +12,6 @@ function OrganizationSettingsLayout({ children }: PropsWithChildren) {
const fullCurrentPath = useCurrentPath()
const [currentPath] = fullCurrentPath.split('#')
- // [Joshen] RE Organization Settings - need to figure out how to enforce MFA across users before this goes live
- const newSecurityPage = useFlag('showOrganizationSecuritySettings')
-
// Hide these settings in the new layout on the following paths
const isHidden = (path: string) => {
return (
@@ -35,7 +31,7 @@ function OrganizationSettingsLayout({ children }: PropsWithChildren) {
label: 'General',
href: `/org/${slug}/general`,
},
- newSecurityPage && {
+ {
label: 'Security',
href: `/org/${slug}/security`,
},