diff --git a/apps/docs/pages/guides/platform/going-into-prod.mdx b/apps/docs/pages/guides/platform/going-into-prod.mdx
index 6e8bd43de81..289e437cda0 100644
--- a/apps/docs/pages/guides/platform/going-into-prod.mdx
+++ b/apps/docs/pages/guides/platform/going-into-prod.mdx
@@ -20,6 +20,8 @@ After developing your project and deciding it's Production Ready, you should run
- Enable replication on tables containing sensitive data by enabling Row Level Security (RLS) and setting row security policies:
- Go to the Authentication > Policies page in the Supabase Dashboard to enable RLS and create security policies.
- Go to the Database > Replication page in the Supabase Dashboard to manage replication tables.
+- Turn on [SSL Enforcement](/docs/guides/platform/ssl-enforcement)
+- Enable [Network Restrictions](/docs/guides/platform/network-restrictions) for your database.
- Enable 2FA on GitHub. Since your GitHub account gives you administrative rights to your Supabase project, you should protect it with a strong password and 2FA using a U2F key or a TOTP app.
- Ensure email confirmations are enabled in the `Settings > Auth` page.
- Use a custom SMTP server for auth emails so that your users can see that the mails are coming from a trusted domain (preferably the same domain that your app is hosted on). Grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.
diff --git a/apps/docs/pages/guides/platform/shared-responsibility-model.mdx b/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
index 2ff4ac625ac..5675f33bfd0 100644
--- a/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
+++ b/apps/docs/pages/guides/platform/shared-responsibility-model.mdx
@@ -46,6 +46,17 @@ You are responsible for using best-practices to optimize and manage your databas
You are responsible of provisioning enough compute to run the workload that your application requires. The Supabase Dashboard provides [observability tooling](https://supabase.com/dashboard/project/_/reports/database) to help with this.
+## Managing healthcare data
+
+You can use Supabase to store and process Protected Health Information (PHI). You are responsible for the following
+
+- Signing a Business Associate Agreement with Supabase. Reach out to growth@supabase.io to get started.
+- Enabling [Point in Time Recovery](/docs/guides/platform/backups#point-in-time-recovery).
+- Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement).
+- Enabling [Network Restrictions](/docs/guides/platform/network-restrictions).
+- Disabling [Supabase AI editor](https://supabase.com/dashboard/org/_/general) in our dashboard.
+- Encrypting PHI in your database. Consider using pgsodium's [Transparent Column Encryption](https://github.com/michelp/pgsodium#transparent-column-encryption) which comes bundled in with every Supabase project.
+
export const Page = ({ children }) =>
export default Page
diff --git a/apps/www/_blog/2023-08-11-supabase-soc2-hipaa.mdx b/apps/www/_blog/2023-08-11-supabase-soc2-hipaa.mdx
new file mode 100644
index 00000000000..5b336951f50
--- /dev/null
+++ b/apps/www/_blog/2023-08-11-supabase-soc2-hipaa.mdx
@@ -0,0 +1,82 @@
+---
+title: 'Supabase is now HIPAA and SOC2 Type 2 compliant'
+description: 'This documents our journey from SOC2 Type 1 to SOC2 Type2 and HIPAA compliance. You can start building healthcare apps on Supabase today.'
+launchweek: 8
+tags:
+ - launch-week
+ - security
+date: '2023-08-11'
+published_at: '2023-08-11T09:00:00.000-07:00'
+toc_depth: 3
+author: inian
+image: launch-week-8/day-5/OG-day5-compliance.jpg
+thumb: launch-week-8/day-5/thumb-day5-compliance.jpg
+---
+
+While we weren’t [planning](https://news.ycombinator.com/item?id=35526018) to do anything official for this announcement, [the customer is always right](https://news.ycombinator.com/item?id=35555756).
+
+Supabase is now officially SOC2 Type 2 and HIPAA compliant.
+
+That’s all you need to know. The rest of this blog post will give you some background and what to expect if you’re planning to go through the same process.
+
+## SOC2
+
+We previously [discussed](https://supabase.com/blog/supabase-soc2) the process the SOC2 Type 1. To recap,
+
+1. Type 1 certification verifies adherence to the guidelines at a specific _point in time_.
+2. Type 2 certification verifies compliance over a _period of time_.
+
+We received our Type 2 certification on May 22nd of this year and we plan to conduct annual Type 2 audits to ensure adherence to SOC2 guidelines.
+
+We used the same auditor for the Type 2 certification and knew mostly what to expect. Some of our internal processes needed to change to make it easier to the evidence for our auditor. Examples of the kind of requests our auditor would ask for:
+
+- List of all incidents which happened in a given time period. The postmortem for a few incidents from that list that the auditor chooses.
+- List of all access requests in a given time period.
+- List of vulnerabilities and when they were fixed
+- List of Data deletion requests and evidence that a particular request was actioned on within our SLA.
+
+Some of these were readily available in [Vanta](https://www.vanta.com/), our compliance monitoring tool. For others, we had to develop new processes to ensure that this information was all readily available. The Type 2 audit involves gathering a lot more evidence than the Type 1 audit. If we didn’t have proper systems and process in place before the audit, it would have been painful during evidence collection.
+
+## HIPAA
+
+Health Insurance Portability and Accountability Act (HIPAA) is a US law that sets national standards for protecting individuals' medical records and personal health information. Companies building applications with sensitive healthcare data must comply with HIPAA to ensure the security and privacy of patients' information.
+
+A couple of definitions before go further. A **covered entity** refers to healthcare providers, health plans, and health insurance companies. **Business associates** are entities that perform certain functions with protected health information (PHI) on behalf of a covered entity. Both Business Associates and Covered entities are covered (pun intended) under HIPAA. Supabase is a business associate and our customers handling PHI can either be covered entities or other business associates.
+
+We receive many requests from users who want to build healthcare apps on top of Supabase. Since you can [self-host Supabase](https://supabase.com/docs/guides/self-hosting), we often [encourage](https://github.com/orgs/supabase/discussions/1219) these users to do so. Starting today, these users have the option to use our hosted platform too with the HIPAA add-on 🎉.
+
+### Going from SOC2 to HIPAA
+
+
+
+Going from zero to a SOC2 certification was much harder, than going from SOC2 to HIPAA.
+
+We used the same auditor to streamline the process. Many of the controls required for HIPAA compliance could be mapped to the testing they had already done for SOC2. Additional evidence for encryption, audit logs, business continuity and disaster recovery exercises was unnecessary since the auditor already had access to it. And some of the HIPAA checks such as Facility Access Controls were not applicable to us since [we are a remote company](https://supabase.com/blog/why-supabase-remote).
+
+We also had to sign a Business Associate Agreement (BAA) with all of our vendors who would have access to PHI, such as AWS, and ensure that we follow their terms listed in the agreements. For example, when using AWS to store PHI, we could only use their [HIPAA Eligible Services](https://aws.amazon.com/compliance/hipaa-eligible-services-reference/). There were similar requirements from the other vendors we use and to ensure that we were complying with all their requirements.
+
+Similarly when you sign a BAA with us, you have some responsibilities you agree to when using Supabase to store PHI. These are documented in our [shared responsibility doc](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data).
+
+We made a significant change to our incident management process for HIPAA. The [HIPAA Breach Notification](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html) rules have strict requirements for handling breaches. For instance, business associates are required to notify the covered entity within 60 days of a breach. This also required us to appoint a HIPAA Security officer who would be responsible for reviewing any breach for PHI disclosure and communicating it’s impact to the Covered Entity.
+
+
+
+The not-so-fun but important stuff included updating a bunch of our policies to cover HIPAA requirements such as enforcing automatic log-offs as part of our workstation security policy. Shopping for a good Technology Errors and Omissions Insurance plan was another boring but important thing we had to finalize in the off-chance that we get hacked despite all our measures. [HIPAA fines](https://www.strongdm.com/blog/hipaa-violation-penalties) are no joke, you could rake up to 1.9 million dollars per violation per calendar year depending the severity of the breach!
+
+## Build Healthcare Apps on Supabase
+
+If you want to start developing healthcare apps on Supabase, reach out to our team [here](https://forms.supabase.com/hipaa) to sign our BAA. We are excited to see what you build!
+
+## More Launch Week 8
+
+- [Supabase Local Dev: migrations, branching, and observability](https://supabase.com/blog/supabase-local-dev)
+- [Hugging Face is now supported in Supabase](https://supabase.com/blog/hugging-face-supabase)
+- [Launch Week 8](https://supabase.com/launch-week)
+- [Coding the stars - an interactive constellation with Three.js and React Three Fiber](https://supabase.com/blog/interactive-constellation-threejs-react-three-fiber)
+- [Why we'll stay remote](https://supabase.com/blog/why-supabase-remote)
+- [Postgres Language Server](https://github.com/supabase/postgres_lsp)
diff --git a/apps/www/data/Footer.json b/apps/www/data/Footer.json
index cef2e1e8201..cf4f5de392d 100644
--- a/apps/www/data/Footer.json
+++ b/apps/www/data/Footer.json
@@ -70,6 +70,10 @@
{
"text": "SOC2",
"url": "https://forms.supabase.com/soc2"
+ },
+ {
+ "text": "HIPAA",
+ "url": "https://forms.supabase.com/hipaa"
}
]
},
diff --git a/apps/www/lib/mdx/mdxComponents.tsx b/apps/www/lib/mdx/mdxComponents.tsx
index d69442d9cc0..6568225002b 100644
--- a/apps/www/lib/mdx/mdxComponents.tsx
+++ b/apps/www/lib/mdx/mdxComponents.tsx
@@ -97,15 +97,15 @@ export default function mdxComponents(type?: 'blog' | 'lp' | undefined) {
{zoomable ? (
) : (
)}
diff --git a/apps/www/pages/security.mdx b/apps/www/pages/security.mdx
index 0fc22da630e..012ce8008ef 100644
--- a/apps/www/pages/security.mdx
+++ b/apps/www/pages/security.mdx
@@ -7,7 +7,7 @@ import {
CreditCardIcon,
ClipboardCheckIcon,
} from '@heroicons/react/outline'
-import { Button, IconGitHub } from 'ui'
+import { Button, IconGitHub, IconActivity } from 'ui'
import Layout from '../layouts/Layout'
import Link from 'next/link'
@@ -52,10 +52,21 @@ export const Section = ({ children, icon, img }) => (
### SOC 2
-Supabase is SOC2 Type 2 compliant. Enterprise and Teams customers can request a copy of our SOC2 [here](https://forms.supabase.com/soc2).
+Supabase is SOC2 Type 2 compliant. Enterprise and Teams customers can request a copy of our SOC2 report [here](https://forms.supabase.com/soc2).
-
-
+
+
+
+
+
+}>
+
+### HIPAA
+
+Supabase is HIPAA compliant. Enterprise and Teams customers can request to sign our BAA [here](https://forms.supabase.com/hipaa).
+
+
+
@@ -91,7 +102,7 @@ Members of organizations in Supabase can be granted access to specific resources
All customer databases are backed up every day.
-Enterprise customers have access to Point in Time Recovery which enables restoring the database to any point in time.
+Point in Time Recovery allows restoring the database to any point in time. Customers from the Pro plan have access to this feature as an add-on.
@@ -124,15 +135,27 @@ In addition to internal security reviews, we use various tools to scan our code
-
Request for our SOC2 documents
+
Documents Center
-As a database company, being SOC2 compliant is important when handling sensitive customer data. Access more of Supabase’s security information by requesting for our latest SOC2 documents below (available for Enterprise and Teams customers only).
+As a database company, being SOC2 compliant is important when handling sensitive customer data. Access Supabase’s security policies by requesting for our latest SOC2 report.
+
+You can build healthcare apps on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data).
+
+
+
+
+
diff --git a/apps/www/public/images/blog/launch-week-8/day-5/OG-day5-compliance.jpg b/apps/www/public/images/blog/launch-week-8/day-5/OG-day5-compliance.jpg
new file mode 100644
index 00000000000..b28fa79cdde
Binary files /dev/null and b/apps/www/public/images/blog/launch-week-8/day-5/OG-day5-compliance.jpg differ
diff --git a/apps/www/public/images/blog/launch-week-8/day-5/data-breach-2.png b/apps/www/public/images/blog/launch-week-8/day-5/data-breach-2.png
new file mode 100644
index 00000000000..9bb70dd8752
Binary files /dev/null and b/apps/www/public/images/blog/launch-week-8/day-5/data-breach-2.png differ
diff --git a/apps/www/public/images/blog/launch-week-8/day-5/soc2-to-hipaa.png b/apps/www/public/images/blog/launch-week-8/day-5/soc2-to-hipaa.png
new file mode 100644
index 00000000000..140cd1acd55
Binary files /dev/null and b/apps/www/public/images/blog/launch-week-8/day-5/soc2-to-hipaa.png differ
diff --git a/apps/www/public/images/blog/launch-week-8/day-5/thumb-day5-compliance.jpg b/apps/www/public/images/blog/launch-week-8/day-5/thumb-day5-compliance.jpg
new file mode 100644
index 00000000000..a9d44b7a87c
Binary files /dev/null and b/apps/www/public/images/blog/launch-week-8/day-5/thumb-day5-compliance.jpg differ
diff --git a/apps/www/public/images/security/HIPAA.svg b/apps/www/public/images/security/HIPAA.svg
new file mode 100644
index 00000000000..37f55a12156
--- /dev/null
+++ b/apps/www/public/images/security/HIPAA.svg
@@ -0,0 +1,19 @@
+
diff --git a/apps/www/public/images/security/soc2-type2.svg b/apps/www/public/images/security/soc2-type2.svg
new file mode 100644
index 00000000000..f8fd1235a21
--- /dev/null
+++ b/apps/www/public/images/security/soc2-type2.svg
@@ -0,0 +1,6 @@
+
diff --git a/apps/www/public/rss.xml b/apps/www/public/rss.xml
index 14343dac0db..d0c6f3a986b 100644
--- a/apps/www/public/rss.xml
+++ b/apps/www/public/rss.xml
@@ -14,6 +14,20 @@
Supavisor is a scalable, cloud-native Postgres connection pooler. We connected a million clients to it to see how it performs.Thu, 10 Aug 2023 22:00:00 GMT
+
+ https://supabase.com/blog/supabase-soc2-hipaa
+ Supabase is now HIPAA and SOC2 Type 2 compliant
+ https://supabase.com/blog/supabase-soc2-hipaa
+ This documents our journey from SOC2 Type 1 to SOC2 Type2 and HIPAA compliance. You can start building healthcare apps on Supabase today.
+ Thu, 10 Aug 2023 22:00:00 GMT
+
+
+ https://supabase.com/blog/launch-week-8-community-highlights
+ Launch Week 8 Community Highlights
+ https://supabase.com/blog/launch-week-8-community-highlights
+ Highlights from the community for the past 4 months.
+ Thu, 10 Aug 2023 22:00:00 GMT
+https://supabase.com/blog/supabase-integrations-marketplaceSupabase Integrations Marketplace
diff --git a/packages/shared-data/plans.ts b/packages/shared-data/plans.ts
index 33851d576b0..66c7a841bc9 100644
--- a/packages/shared-data/plans.ts
+++ b/packages/shared-data/plans.ts
@@ -86,8 +86,7 @@ export const plans: PricingInformation[] = [
'7-day log retention',
'Email support',
],
- footer:
- 'Your cost control settings determine if you allow over-usage.',
+ footer: 'Your cost control settings determine if you allow over-usage.',
preface: 'Everything in the Free plan, plus:',
cta: 'Get Started',
},
@@ -107,6 +106,7 @@ export const plans: PricingInformation[] = [
'Daily backups stored for 14 days',
'Standardised Security Questionnaire',
'SOC2',
+ 'HIPAA',
'SSO for Supabase Dashboard',
'Priority email support & SLAs',
'28-day log retention',
diff --git a/packages/shared-data/pricing.ts b/packages/shared-data/pricing.ts
index 5e0d5c1b83a..691841d690b 100644
--- a/packages/shared-data/pricing.ts
+++ b/packages/shared-data/pricing.ts
@@ -291,6 +291,16 @@ export const pricing: Pricing = {
},
usage_based: true,
},
+ {
+ title: 'Bring your own storage provider',
+ plans: {
+ free: false,
+ pro: false,
+ team: false,
+ enterprise: true,
+ },
+ usage_based: false,
+ },
],
},
edge_functions: {
@@ -477,6 +487,19 @@ export const pricing: Pricing = {
},
usage_based: false,
},
+ {
+ title: 'HIPAA',
+ plans: {
+ free: false,
+ pro: false,
+ team: true,
+ enterprise: true,
+ },
+ tooltips: {
+ main: 'Available as a paid add-on on Team plan and above.',
+ },
+ usage_based: false,
+ },
{
title: 'SSO',
plans: {
@@ -530,6 +553,19 @@ export const pricing: Pricing = {
},
usage_based: false,
},
+ {
+ title: 'Bring your own cloud deployment options',
+ tooltips: {
+ main: 'On-Premises, single tenant, and managed dedicated cloud provider instance options',
+ },
+ plans: {
+ free: false,
+ pro: false,
+ team: false,
+ enterprise: true,
+ },
+ usage_based: false,
+ },
],
},
support: {