design demo: security page content additions (content-only) (#48403)

## Summary

- Adds four missing content cards to the existing `security.mdx` using
the same `Section` component and grid already on the page — no new UI
components or features
- Cards added: **GDPR & European Compliance**, **Data Residency**,
**Data Processing Agreement**, **Shared Responsibility**
- Also fixes the HIPAA shared responsibility link path (`/deployment/`
not `/platform/`)

Worth validating still.

## What this is

A content-only drop-in that addresses some gaps

## What's out of scope here

- No sticky nav, tables, plan comparison grids, or new components
- No DPA request automation — just a plain link to `/legal/dpa`
- No plan-gating claims (removed — accuracy unconfirmed)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Reorganized the security page into clearer, grouped sections
(Compliance, Data, Configuration, and Misc) for easier navigation.
* Expanded compliance coverage with HIPAA, ISO 27001, GDPR & European
compliance, and updated shared responsibility details.
* Added new content for data residency and a Data Processing Agreement
section.
* Reordered configuration items (multi-factor authentication, role-based
access, vulnerability management, DDoS) and moved payment processing
into the Misc section.
  * Updated icons and card layout visuals throughout the page.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-07-31 08:36:03 +00:00
1 parent c4c58ef3e3
commit ca94d842a7
1 file changed
+119 -28
+119 -28
View File
@@ -7,7 +7,7 @@ import {
UserGroupIcon,
} from '@heroicons/react/outline'
import SecurityNewsletterForm from '~/components/SecurityNewsletterForm'
import { Activity, Lock } from 'lucide-react'
import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react'
import Layout from '../layouts/Layout'
@@ -44,20 +44,19 @@ export const Section = ({ children, icon, img }) => (
</div>
</div>
<div className="section-container mb-16">
<div className="section-container mb-16 flex flex-col gap-12">
{/* Compliance */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Compliance
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Lock strokeWidth={1}/>}>
### Multi-factor Authentication
Supabase allows users to enable Multi-factor authentication (MFA) on their account.
MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
</Section>
<Section icon={<ShieldCheckIcon strokeWidth={1}/>}>
<Section icon={<Lock strokeWidth={1} />}>
### SOC 2
@@ -71,11 +70,11 @@ Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboa
</Section>
<Section icon={<Activity strokeWidth={1}/>}>
<Section icon={<Activity strokeWidth={1} />}>
### HIPAA
Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data).
Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data).
Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents).
@@ -84,7 +83,8 @@ Enterprise and Team customers can request to sign our BAA [on the dashboard](/da
</div>
</Section>
<Section icon={<ShieldCheckIcon strokeWidth={1}/>}>
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
### ISO 27001
@@ -93,7 +93,32 @@ Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized stan
Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
</Section>
<Section icon={<KeyIcon strokeWidth={1}/>}>
<Section icon={<Globe strokeWidth={1} />}>
### GDPR & European Compliance
Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR.
See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt).
</Section>
</div>
</div>
{/* Data */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Data
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<KeyIcon strokeWidth={1} />}>
### Data Encryption
@@ -103,17 +128,17 @@ Sensitive information like access tokens and keys are encrypted at the applicati
</Section>
<Section icon={<UserGroupIcon strokeWidth={1}/>}>
<Section icon={<Globe strokeWidth={1} />}>
### Role-based access control
### Data Residency
Members of organizations in Supabase can be granted access to specific resources.
When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific.
Read more about [fine grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
See the full list of [available regions](/docs/guides/platform/regions).
</Section>
<Section icon={<RewindIcon strokeWidth={1}/>}>
<Section icon={<RewindIcon strokeWidth={1} />}>
### Backups
@@ -123,17 +148,47 @@ Point in Time Recovery allows restoring the database to any point in time. Custo
</Section>
<Section icon={<CreditCardIcon strokeWidth={1}/>}>
<Section icon={<FileText strokeWidth={1} />}>
### Payment processing
### Data Processing Agreement
Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
</Section>
<Section icon={<ClipboardCheckIcon strokeWidth={1}/>}>
</div>
</div>
{/* Configuration */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Configuration
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Lock strokeWidth={1} />}>
### Multi-factor Authentication
Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
</Section>
<Section icon={<UserGroupIcon strokeWidth={1} />}>
### Role-based access control
Members of organizations in Supabase can be granted access to specific resources.
Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
</Section>
<Section icon={<ClipboardCheckIcon strokeWidth={1} />}>
### Vulnerability Management
@@ -143,7 +198,7 @@ In addition to internal security reviews, we use various tools to scan our code
</Section>
<Section icon={<ShieldCheckIcon strokeWidth={1}/>}>
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
### DDoS Protection
@@ -157,6 +212,42 @@ In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](
</div>
{/* Misc */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Misc
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Scale strokeWidth={1} />}>
### Shared Responsibility
Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls.
Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model).
</Section>
<Section icon={<CreditCardIcon strokeWidth={1} />}>
### Payment processing
Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
</Section>
</div>
</div>
</div>
<div className="section-container mb-16">
<SecurityNewsletterForm />
</div>