mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
docs(security): note July 9 effective date for log_connections default (#47252)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? - docs update Follow-up to DOCS-1080 / PSQL-1307 after #47199 merged. ## What is the current behavior? - Docs state that `log_connections` is off by default for new projects (#47199) but do not note when that platform default takes effect. - The `log_connections=off` default is not live until **July 9, 2026**. ## What is the new behavior? - Adds a shared note admonition (via partial) on all five pages that state the `log_connections=off` default. - Admonition copy: "This default takes effect for new projects from July 9, 2026." ### Proof: admonition renders on preview **Verified:** `supa-mdx-lint` (pass) · Vercel docs preview (all changed pages 200) | Check | Result | |-------|--------| | `supa-mdx-lint` | pass | | Preview — Postgres connection logging | [200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) | | Preview — Logs | [200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections) | | Preview — HIPAA compliance FAQ | [200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance) | | Preview — Shared responsibility model | [200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) | | Preview — SOC 2 compliance | [200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance) | **Screenshots (Default behavior section):**    **Quick review links:** - [Postgres connection logging — Default behavior](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) - [Logs — Logging Postgres connections](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections) - [HIPAA compliance — FAQ](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance) - [Shared responsibility model — Managing healthcare data](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) - [SOC 2 compliance — Customer responsibilities](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance) ## Additional context - Scheduled cleanup PR: #47253 removes this admonition on **July 9, 2026**. - Review screenshots live in `.github/pr-screenshots/docs-1080/` on this branch for PR proof only. ### Test plan - [ ] Open [preview guide](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) — note admonition appears under Default behavior - [ ] Confirm admonition on [Logs](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections), [HIPAA FAQ](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance), [shared responsibility bullet](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data), and [SOC 2 item 5](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance) - [ ] Merge #47253 on July 9 after the platform default is live --------- Co-authored-by: Nik Richers <nik@validmind.ai>
This commit is contained in:
1 parent
e2121aedd8
commit
eecedb44aa
9 files changed
+16
No files matched your search
Binary file not shown.
|
After Width: | Height: | Size: 405 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 424 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 454 KiB |
@@ -0,0 +1,5 @@
|
||||
<Admonition type="note">
|
||||
|
||||
This default takes effect for new projects from July 9, 2026.
|
||||
|
||||
</Admonition>
|
||||
@@ -99,6 +99,9 @@ You can use Supabase to store and process Protected Health Information (PHI). Yo
|
||||
- Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement).
|
||||
- Enabling [Network Restrictions](/docs/guides/platform/network-restrictions).
|
||||
- Keeping [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) enabled. Supabase sets `log_connections` to off by default for new projects. Projects that need HIPAA compliance should keep connection logging on for audit trails, and the Security Advisor warns if it is disabled.
|
||||
|
||||
<$Partial path="log_connections_default_effective_date.mdx" />
|
||||
|
||||
- Complying with encryption requirements in the HIPAA Security Rule. Data is encrypted at rest and in transit by Supabase. You can consider encrypting the data at your application layer.
|
||||
- Not storing PHI in [public Storage buckets](/docs/guides/storage/buckets/fundamentals#public-buckets).
|
||||
- Not [transferring projects](/docs/guides/platform/project-transfer) to a non-HIPAA organization.
|
||||
|
||||
@@ -10,6 +10,8 @@ For security monitoring and compliance audits, Postgres can log connection lifec
|
||||
|
||||
By default, Supabase sets `log_connections` to off for new projects and you must enable it first. This behavior matches common managed Postgres defaults and reduces log volume from high-frequency connection events.
|
||||
|
||||
<$Partial path="log_connections_default_effective_date.mdx" />
|
||||
|
||||
Existing projects may retain different settings depending on plan and compliance configuration:
|
||||
|
||||
- **Team, Enterprise, and HIPAA organizations** — Connection logging is typically enabled to support audit requirements.
|
||||
|
||||
@@ -55,6 +55,8 @@ Yes. Supabase applies the same SOC 2 controls to all environments, with addition
|
||||
|
||||
No. Supabase sets Postgres `log_connections` to off by default for new projects. HIPAA and high-compliance projects should keep [connection logging](/docs/guides/platform/postgres-connection-logging) enabled. The Security Advisor warns if it is disabled.
|
||||
|
||||
<$Partial path="log_connections_default_effective_date.mdx" />
|
||||
|
||||
**How often is Supabase audited?**
|
||||
|
||||
Supabase undergoes annual audits. The HIPAA controls are audited during the same audit period as the SOC 2 controls.
|
||||
|
||||
@@ -40,6 +40,8 @@ SOC 2 compliance is a critical aspect of data security for Supabase and our cust
|
||||
4. **Control Compliance**: If a customer needs to be SOC 2 compliant, they should themselves implement the requisite controls and undergo a SOC 2 audit.
|
||||
5. **Audit logging**: Supabase sets [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) to off by default for new projects. If your SOC 2 program requires connection audit evidence, enable connection logging and define how you retain and review those logs.
|
||||
|
||||
<$Partial path="log_connections_default_effective_date.mdx" />
|
||||
|
||||
#### Shared responsibilities
|
||||
|
||||
1. **Data Security**: Both customers and Supabase share the responsibility of ensuring data security. While the Supabase, as the provider, implements the security controls, the customer must ensure that their use of the Supabase platform does not compromise these controls.
|
||||
|
||||
@@ -147,6 +147,8 @@ Do not log Personal Identifiable Information (PII) within the `User-Agent` heade
|
||||
|
||||
Postgres can log connection lifecycle events to your project's Postgres logs, for example when a client connects or authenticates. By default, Supabase sets `log_connections` to off for new projects and you must enable it first.
|
||||
|
||||
<$Partial path="log_connections_default_effective_date.mdx" />
|
||||
|
||||
To enable connection logging for audit or compliance, see [Postgres connection logging](/docs/guides/platform/postgres-connection-logging).
|
||||
|
||||
In the [Logs Explorer](/dashboard/project/_/logs-explorer), connection lifecycle messages may be hidden by default. Use the connection logs filter in the sidebar to show them.
|
||||
|
||||
Reference in new issue
Block a user