From ca94d842a7b3e5bdaeb295ee3b786dc9c8678a00 Mon Sep 17 00:00:00 2001 From: Steven Eubank <47563310+smeubank@users.noreply.github.com> Date: Fri, 31 Jul 2026 10:36:03 +0200 Subject: [PATCH] design demo: security page content additions (content-only) (#48403) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Summary - Adds four missing content cards to the existing `security.mdx` using the same `Section` component and grid already on the page — no new UI components or features - Cards added: **GDPR & European Compliance**, **Data Residency**, **Data Processing Agreement**, **Shared Responsibility** - Also fixes the HIPAA shared responsibility link path (`/deployment/` not `/platform/`) Worth validating still. ## What this is A content-only drop-in that addresses some gaps ## What's out of scope here - No sticky nav, tables, plan comparison grids, or new components - No DPA request automation — just a plain link to `/legal/dpa` - No plan-gating claims (removed — accuracy unconfirmed) ## Summary by CodeRabbit * **Documentation** * Reorganized the security page into clearer, grouped sections (Compliance, Data, Configuration, and Misc) for easier navigation. * Expanded compliance coverage with HIPAA, ISO 27001, GDPR & European compliance, and updated shared responsibility details. * Added new content for data residency and a Data Processing Agreement section. * Reordered configuration items (multi-factor authentication, role-based access, vulnerability management, DDoS) and moved payment processing into the Misc section. * Updated icons and card layout visuals throughout the page. --------- Co-authored-by: Claude Sonnet 4.6 Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Nik Richers --- apps/www/pages/security.mdx | 147 +++++++++++++++++++++++++++++------- 1 file changed, 119 insertions(+), 28 deletions(-) diff --git a/apps/www/pages/security.mdx b/apps/www/pages/security.mdx index 802905dd165..3192ebfa4c6 100644 --- a/apps/www/pages/security.mdx +++ b/apps/www/pages/security.mdx @@ -7,7 +7,7 @@ import { UserGroupIcon, } from '@heroicons/react/outline' import SecurityNewsletterForm from '~/components/SecurityNewsletterForm' -import { Activity, Lock } from 'lucide-react' +import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react' import Layout from '../layouts/Layout' @@ -44,20 +44,19 @@ export const Section = ({ children, icon, img }) => ( -
+
+ +{/* Compliance */} + +
+ +

+ Compliance +

-
}> - -### Multi-factor Authentication - -Supabase allows users to enable Multi-factor authentication (MFA) on their account. -MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity. - -
- -
}> +
}> ### SOC 2 @@ -71,11 +70,11 @@ Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboa
-
}> +
}> ### HIPAA -Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/platform/shared-responsibility-model#managing-healthcare-data). +Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data). Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents). @@ -84,7 +83,8 @@ Enterprise and Team customers can request to sign our BAA [on the dashboard](/da
-
}> + +
}> ### ISO 27001 @@ -93,7 +93,32 @@ Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized stan Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
-
}> + +
}> + +### GDPR & European Compliance + +Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR. + +See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt). + +
+ +
+ +
+ +{/* Data */} + +
+ +

+ Data +

+ +
+ +
}> ### Data Encryption @@ -103,17 +128,17 @@ Sensitive information like access tokens and keys are encrypted at the applicati
-
}> +
}> -### Role-based access control +### Data Residency -Members of organizations in Supabase can be granted access to specific resources. +When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific. -Read more about [fine grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access. +See the full list of [available regions](/docs/guides/platform/regions).
-
}> +
}> ### Backups @@ -123,17 +148,47 @@ Point in Time Recovery allows restoring the database to any point in time. Custo
-
}> +
}> -### Payment processing +### Data Processing Agreement -Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers. - -Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry. +A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
-
}> +
+ +
+ +{/* Configuration */} + +
+ +

+ Configuration +

+ +
+ +
}> + +### Multi-factor Authentication + +Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity. + +
+ +
}> + +### Role-based access control + +Members of organizations in Supabase can be granted access to specific resources. + +Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access. + +
+ +
}> ### Vulnerability Management @@ -143,7 +198,7 @@ In addition to internal security reviews, we use various tools to scan our code
-
}> +
}> ### DDoS Protection @@ -157,6 +212,42 @@ In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](
+{/* Misc */} + +
+ +

+ Misc +

+ +
+ +
}> + +### Shared Responsibility + +Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls. + +Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model). + +
+ +
}> + +### Payment processing + +Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers. + +Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry. + +
+ +
+ +
+ +
+