diff --git a/.github/pr-screenshots/docs-1080/pr1-hipaa-compliance.png b/.github/pr-screenshots/docs-1080/pr1-hipaa-compliance.png new file mode 100644 index 00000000000..62addb4331d Binary files /dev/null and b/.github/pr-screenshots/docs-1080/pr1-hipaa-compliance.png differ diff --git a/.github/pr-screenshots/docs-1080/pr1-logs.png b/.github/pr-screenshots/docs-1080/pr1-logs.png new file mode 100644 index 00000000000..34a907a0e89 Binary files /dev/null and b/.github/pr-screenshots/docs-1080/pr1-logs.png differ diff --git a/.github/pr-screenshots/docs-1080/pr1-postgres-connection-logging.png b/.github/pr-screenshots/docs-1080/pr1-postgres-connection-logging.png new file mode 100644 index 00000000000..3751f465602 Binary files /dev/null and b/.github/pr-screenshots/docs-1080/pr1-postgres-connection-logging.png differ diff --git a/apps/docs/content/_partials/log_connections_default_effective_date.mdx b/apps/docs/content/_partials/log_connections_default_effective_date.mdx new file mode 100644 index 00000000000..67a85fc52c1 --- /dev/null +++ b/apps/docs/content/_partials/log_connections_default_effective_date.mdx @@ -0,0 +1,5 @@ + + +This default takes effect for new projects from July 9, 2026. + + diff --git a/apps/docs/content/guides/deployment/shared-responsibility-model.mdx b/apps/docs/content/guides/deployment/shared-responsibility-model.mdx index e6d82cc9638..5cfed3746e3 100644 --- a/apps/docs/content/guides/deployment/shared-responsibility-model.mdx +++ b/apps/docs/content/guides/deployment/shared-responsibility-model.mdx @@ -99,6 +99,9 @@ You can use Supabase to store and process Protected Health Information (PHI). Yo - Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement). - Enabling [Network Restrictions](/docs/guides/platform/network-restrictions). - Keeping [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) enabled. Supabase sets `log_connections` to off by default for new projects. Projects that need HIPAA compliance should keep connection logging on for audit trails, and the Security Advisor warns if it is disabled. + +<$Partial path="log_connections_default_effective_date.mdx" /> + - Complying with encryption requirements in the HIPAA Security Rule. Data is encrypted at rest and in transit by Supabase. You can consider encrypting the data at your application layer. - Not storing PHI in [public Storage buckets](/docs/guides/storage/buckets/fundamentals#public-buckets). - Not [transferring projects](/docs/guides/platform/project-transfer) to a non-HIPAA organization. diff --git a/apps/docs/content/guides/platform/postgres-connection-logging.mdx b/apps/docs/content/guides/platform/postgres-connection-logging.mdx index 866336b8046..273cb11a122 100644 --- a/apps/docs/content/guides/platform/postgres-connection-logging.mdx +++ b/apps/docs/content/guides/platform/postgres-connection-logging.mdx @@ -10,6 +10,8 @@ For security monitoring and compliance audits, Postgres can log connection lifec By default, Supabase sets `log_connections` to off for new projects and you must enable it first. This behavior matches common managed Postgres defaults and reduces log volume from high-frequency connection events. +<$Partial path="log_connections_default_effective_date.mdx" /> + Existing projects may retain different settings depending on plan and compliance configuration: - **Team, Enterprise, and HIPAA organizations** — Connection logging is typically enabled to support audit requirements. diff --git a/apps/docs/content/guides/security/hipaa-compliance.mdx b/apps/docs/content/guides/security/hipaa-compliance.mdx index c387b5c6947..84ee2a7640d 100644 --- a/apps/docs/content/guides/security/hipaa-compliance.mdx +++ b/apps/docs/content/guides/security/hipaa-compliance.mdx @@ -55,6 +55,8 @@ Yes. Supabase applies the same SOC 2 controls to all environments, with addition No. Supabase sets Postgres `log_connections` to off by default for new projects. HIPAA and high-compliance projects should keep [connection logging](/docs/guides/platform/postgres-connection-logging) enabled. The Security Advisor warns if it is disabled. +<$Partial path="log_connections_default_effective_date.mdx" /> + **How often is Supabase audited?** Supabase undergoes annual audits. The HIPAA controls are audited during the same audit period as the SOC 2 controls. diff --git a/apps/docs/content/guides/security/soc-2-compliance.mdx b/apps/docs/content/guides/security/soc-2-compliance.mdx index 7e202e4d2a4..e982263ab2c 100644 --- a/apps/docs/content/guides/security/soc-2-compliance.mdx +++ b/apps/docs/content/guides/security/soc-2-compliance.mdx @@ -40,6 +40,8 @@ SOC 2 compliance is a critical aspect of data security for Supabase and our cust 4. **Control Compliance**: If a customer needs to be SOC 2 compliant, they should themselves implement the requisite controls and undergo a SOC 2 audit. 5. **Audit logging**: Supabase sets [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) to off by default for new projects. If your SOC 2 program requires connection audit evidence, enable connection logging and define how you retain and review those logs. +<$Partial path="log_connections_default_effective_date.mdx" /> + #### Shared responsibilities 1. **Data Security**: Both customers and Supabase share the responsibility of ensuring data security. While the Supabase, as the provider, implements the security controls, the customer must ensure that their use of the Supabase platform does not compromise these controls. diff --git a/apps/docs/content/guides/telemetry/logs.mdx b/apps/docs/content/guides/telemetry/logs.mdx index 9f5d9ae85bc..0d41674f528 100644 --- a/apps/docs/content/guides/telemetry/logs.mdx +++ b/apps/docs/content/guides/telemetry/logs.mdx @@ -147,6 +147,8 @@ Do not log Personal Identifiable Information (PII) within the `User-Agent` heade Postgres can log connection lifecycle events to your project's Postgres logs, for example when a client connects or authenticates. By default, Supabase sets `log_connections` to off for new projects and you must enable it first. +<$Partial path="log_connections_default_effective_date.mdx" /> + To enable connection logging for audit or compliance, see [Postgres connection logging](/docs/guides/platform/postgres-connection-logging). In the [Logs Explorer](/dashboard/project/_/logs-explorer), connection lifecycle messages may be hidden by default. Use the connection logs filter in the sidebar to show them.