diff --git a/apps/www/pages/security.mdx b/apps/www/pages/security.mdx
index 802905dd165..3192ebfa4c6 100644
--- a/apps/www/pages/security.mdx
+++ b/apps/www/pages/security.mdx
@@ -7,7 +7,7 @@ import {
UserGroupIcon,
} from '@heroicons/react/outline'
import SecurityNewsletterForm from '~/components/SecurityNewsletterForm'
-import { Activity, Lock } from 'lucide-react'
+import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react'
import Layout from '../layouts/Layout'
@@ -44,20 +44,19 @@ export const Section = ({ children, icon, img }) => (
-
+
+
+{/* Compliance */}
+
+
+
+
+ Compliance
+
-}>
-
-### Multi-factor Authentication
-
-Supabase allows users to enable Multi-factor authentication (MFA) on their account.
-MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
-
-
-
-}>
+}>
### SOC 2
@@ -71,11 +70,11 @@ Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboa
-}>
+}>
### HIPAA
-Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data).
+Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data).
Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents).
@@ -84,7 +83,8 @@ Enterprise and Team customers can request to sign our BAA [on the dashboard](/da
-
}>
+
+}>
### ISO 27001
@@ -93,7 +93,32 @@ Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized stan
Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
-
}>
+
+}>
+
+### GDPR & European Compliance
+
+Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR.
+
+See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt).
+
+
+
+
+
+
+
+{/* Data */}
+
+
+
+
+ Data
+
+
+
+
+}>
### Data Encryption
@@ -103,17 +128,17 @@ Sensitive information like access tokens and keys are encrypted at the applicati
-}>
+}>
-### Role-based access control
+### Data Residency
-Members of organizations in Supabase can be granted access to specific resources.
+When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific.
-Read more about [fine grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
+See the full list of [available regions](/docs/guides/platform/regions).
-}>
+}>
### Backups
@@ -123,17 +148,47 @@ Point in Time Recovery allows restoring the database to any point in time. Custo
-}>
+}>
-### Payment processing
+### Data Processing Agreement
-Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
-
-Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
+A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
-
+
+
+
+{/* Configuration */}
+
+
+
+
+ Configuration
+
+
+
+
+}>
+
+### Multi-factor Authentication
+
+Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
+
+
+
+}>
+
+### Role-based access control
+
+Members of organizations in Supabase can be granted access to specific resources.
+
+Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
+
+
+
+}>
### Vulnerability Management
@@ -143,7 +198,7 @@ In addition to internal security reviews, we use various tools to scan our code
-}>
+}>
### DDoS Protection
@@ -157,6 +212,42 @@ In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](
+{/* Misc */}
+
+
+
+
+ Misc
+
+
+
+
+}>
+
+### Shared Responsibility
+
+Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls.
+
+Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model).
+
+
+
+}>
+
+### Payment processing
+
+Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
+
+Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
+
+
+
+
+
+
+
+
+