diff --git a/apps/www/pages/security.mdx b/apps/www/pages/security.mdx index 802905dd165..3192ebfa4c6 100644 --- a/apps/www/pages/security.mdx +++ b/apps/www/pages/security.mdx @@ -7,7 +7,7 @@ import { UserGroupIcon, } from '@heroicons/react/outline' import SecurityNewsletterForm from '~/components/SecurityNewsletterForm' -import { Activity, Lock } from 'lucide-react' +import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react' import Layout from '../layouts/Layout' @@ -44,20 +44,19 @@ export const Section = ({ children, icon, img }) => ( -
+
+ +{/* Compliance */} + +
+ +

+ Compliance +

-
}> - -### Multi-factor Authentication - -Supabase allows users to enable Multi-factor authentication (MFA) on their account. -MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity. - -
- -
}> +
}> ### SOC 2 @@ -71,11 +70,11 @@ Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboa
-
}> +
}> ### HIPAA -Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data). +Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data). Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents). @@ -84,7 +83,8 @@ Enterprise and Team customers can request to sign our BAA [on the dashboard](/da
-
}> + +
}> ### ISO 27001 @@ -93,7 +93,32 @@ Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized stan Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
-
}> + +
}> + +### GDPR & European Compliance + +Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR. + +See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt). + +
+ +
+ +
+ +{/* Data */} + +
+ +

+ Data +

+ +
+ +
}> ### Data Encryption @@ -103,17 +128,17 @@ Sensitive information like access tokens and keys are encrypted at the applicati
-
}> +
}> -### Role-based access control +### Data Residency -Members of organizations in Supabase can be granted access to specific resources. +When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific. -Read more about [fine grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access. +See the full list of [available regions](/docs/guides/platform/regions).
-
}> +
}> ### Backups @@ -123,17 +148,47 @@ Point in Time Recovery allows restoring the database to any point in time. Custo
-
}> +
}> -### Payment processing +### Data Processing Agreement -Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers. - -Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry. +A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
-
}> +
+ +
+ +{/* Configuration */} + +
+ +

+ Configuration +

+ +
+ +
}> + +### Multi-factor Authentication + +Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity. + +
+ +
}> + +### Role-based access control + +Members of organizations in Supabase can be granted access to specific resources. + +Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access. + +
+ +
}> ### Vulnerability Management @@ -143,7 +198,7 @@ In addition to internal security reviews, we use various tools to scan our code
-
}> +
}> ### DDoS Protection @@ -157,6 +212,42 @@ In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](
+{/* Misc */} + +
+ +

+ Misc +

+ +
+ +
}> + +### Shared Responsibility + +Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls. + +Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model). + +
+ +
}> + +### Payment processing + +Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers. + +Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry. + +
+ +
+ +
+ +
+