mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature ## What is the current behavior? Region and data residency information is split across docs, `/security`, and legal pages. [MARKET-1866](https://linear.app/supabase/issue/MARKET-1866/package-and-display-available-regions-better-on-website) ## What is the new behavior? Adds `/regions`: a catalog of all 17 regions generated from `regions.ts`, plus what stays in-region, the Europe vs EU caveat, and links to the DPA, GDPR guide, sub-processor list, and security page. Regions is in the footer under Security & Compliance. The security page residency card now links here. ## Test plan - [ ] Open `/regions` in light and dark mode - [ ] Confirm the region count and list match `packages/shared-data/regions.ts` - [ ] Confirm footer Regions link and `/security` residency link go to `/regions` Made with [Cursor](https://cursor.com) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added a Regions page showcasing available AWS regions by geography. - Added an interactive map and region list with selection, hover states, keyboard accessibility, and residency badges. - Included data residency guidance, legal resources, and a call-to-action for next steps. - Added Regions links in the site footer and security documentation. - **Documentation** - Updated agent skill resources with expanded troubleshooting and operational guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Francesco Sansalvadore <f.sansalvadore@gmail.com>
256 lines
7.8 KiB
Plaintext
256 lines
7.8 KiB
Plaintext
import {
|
|
ClipboardCheckIcon,
|
|
CreditCardIcon,
|
|
KeyIcon,
|
|
RewindIcon,
|
|
ShieldCheckIcon,
|
|
UserGroupIcon,
|
|
} from '@heroicons/react/outline'
|
|
import SecurityNewsletterForm from '~/components/SecurityNewsletterForm'
|
|
import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react'
|
|
|
|
import Layout from '../layouts/Layout'
|
|
|
|
export const meta = {
|
|
type: 'lp',
|
|
title: 'Security at Supabase',
|
|
description:
|
|
'Supabase is trusted by thousands of developers for building and deploying secure applications.',
|
|
}
|
|
|
|
export const Section = ({ children, icon, img }) => (
|
|
<div>
|
|
{icon && (
|
|
<div className="border shadow-background-surface-300 not-prose bg-surface-100 -mb-4 flex h-10 w-10 items-center justify-center rounded-full">
|
|
<figure className="w-5 h-5 flex items-center justify-center">{icon}</figure>
|
|
</div>
|
|
)}
|
|
{img && <div className="-mb-4 flex h-12 w-12 items-center justify-center">{img}</div>}
|
|
{children}
|
|
</div>
|
|
)
|
|
|
|
<div className="section-container grid grid-cols-12 items-center my-8">
|
|
<div className="col-span-12 lg:col-span-6">
|
|
<h1 className="xl:text-5xl mb-4 [&_p]:m-0">Security at Supabase</h1>
|
|
<h2 className="text-xl text-foreground-light max-w-xl m-0 [&_p]:m-0">
|
|
Supabase is trusted by thousands of developers for building and deploying secure applications.
|
|
</h2>
|
|
</div>
|
|
<div className="col-span-12 lg:col-span-5 lg:col-start-8 m-0 [&_p]:m-0">
|
|
|
|

|
|
|
|
</div>
|
|
</div>
|
|
|
|
<div className="section-container mb-16 flex flex-col gap-12">
|
|
|
|
{/* Compliance */}
|
|
|
|
<div className="flex flex-col gap-4">
|
|
|
|
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
|
|
Compliance
|
|
</h3>
|
|
|
|
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
|
|
|
|
<Section icon={<Lock strokeWidth={1} />}>
|
|
|
|
### SOC 2
|
|
|
|
Supabase is SOC 2 Type 2 compliant. This is an important security policy when [handling sensitive customer data](/docs/guides/security/soc-2-compliance).
|
|
|
|
Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboard](/dashboard/org/_/documents).
|
|
|
|
<div className="w-32">
|
|
<img src="/images/security/soc2-type2.svg" />
|
|
</div>
|
|
|
|
</Section>
|
|
|
|
<Section icon={<Activity strokeWidth={1} />}>
|
|
|
|
### HIPAA
|
|
|
|
Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data).
|
|
|
|
Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents).
|
|
|
|
<div className="w-32">
|
|
<img src="/images/security/HIPAA.svg" />
|
|
</div>
|
|
|
|
</Section>
|
|
|
|
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
|
|
|
|
### ISO 27001
|
|
|
|
Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized standard for information security management systems (ISMS), confirming that we maintain rigorous controls to protect customer data.
|
|
|
|
Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
|
|
|
|
</Section>
|
|
|
|
<Section icon={<Globe strokeWidth={1} />}>
|
|
|
|
### GDPR & European Compliance
|
|
|
|
Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR.
|
|
|
|
See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt).
|
|
|
|
</Section>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
{/* Data */}
|
|
|
|
<div className="flex flex-col gap-4">
|
|
|
|
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
|
|
Data
|
|
</h3>
|
|
|
|
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
|
|
|
|
<Section icon={<KeyIcon strokeWidth={1} />}>
|
|
|
|
### Data Encryption
|
|
|
|
All customer data is encrypted at rest with AES-256 and in transit via TLS.
|
|
|
|
Sensitive information like access tokens and keys are encrypted at the application level before they are stored in the database.
|
|
|
|
</Section>
|
|
|
|
<Section icon={<Globe strokeWidth={1} />}>
|
|
|
|
### Data Residency
|
|
|
|
When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific.
|
|
|
|
See the full list of [available regions](/regions).
|
|
|
|
</Section>
|
|
|
|
<Section icon={<RewindIcon strokeWidth={1} />}>
|
|
|
|
### Backups
|
|
|
|
All paid customer databases are backed up every day.
|
|
|
|
Point in Time Recovery allows restoring the database to any point in time. Customers from the Pro Plan have access to this feature as an add-on.
|
|
|
|
</Section>
|
|
|
|
<Section icon={<FileText strokeWidth={1} />}>
|
|
|
|
### Data Processing Agreement
|
|
|
|
A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
|
|
|
|
</Section>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
{/* Configuration */}
|
|
|
|
<div className="flex flex-col gap-4">
|
|
|
|
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
|
|
Configuration
|
|
</h3>
|
|
|
|
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
|
|
|
|
<Section icon={<Lock strokeWidth={1} />}>
|
|
|
|
### Multi-factor Authentication
|
|
|
|
Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
|
|
|
|
</Section>
|
|
|
|
<Section icon={<UserGroupIcon strokeWidth={1} />}>
|
|
|
|
### Role-based access control
|
|
|
|
Members of organizations in Supabase can be granted access to specific resources.
|
|
|
|
Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
|
|
|
|
</Section>
|
|
|
|
<Section icon={<ClipboardCheckIcon strokeWidth={1} />}>
|
|
|
|
### Vulnerability Management
|
|
|
|
Supabase works with industry experts to conduct regular penetration tests.
|
|
|
|
In addition to internal security reviews, we use various tools to scan our code for vulnerabilities including [GitHub](https://github.com), [Vanta](https://www.vanta.com/), and [DepthFirst](https://depthfirst.com/).
|
|
|
|
</Section>
|
|
|
|
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
|
|
|
|
### DDoS Protection
|
|
|
|
Supabase combats Distributed Denial of Service attacks in several ways to mitigate resource abuse and prevent runaway bills.
|
|
|
|
In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](https://github.com/fail2ban/fail2ban) to prevent brute force logins. Users can [customize rate limits](/docs/guides/platform/going-into-prod#rate-limiting-resource-allocation--abuse-prevention) for critical API routes and set [spend caps](/docs/guides/platform/cost-control#spend-cap) to prevent surprise bills.
|
|
|
|
</Section>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
{/* Misc */}
|
|
|
|
<div className="flex flex-col gap-4">
|
|
|
|
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
|
|
Misc
|
|
</h3>
|
|
|
|
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
|
|
|
|
<Section icon={<Scale strokeWidth={1} />}>
|
|
|
|
### Shared Responsibility
|
|
|
|
Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls.
|
|
|
|
Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model).
|
|
|
|
</Section>
|
|
|
|
<Section icon={<CreditCardIcon strokeWidth={1} />}>
|
|
|
|
### Payment processing
|
|
|
|
Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
|
|
|
|
Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
|
|
|
|
</Section>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
|
|
<div className="section-container mb-16">
|
|
<SecurityNewsletterForm />
|
|
</div>
|
|
|
|
export default (context) => <Layout meta={meta} children={context.children} context={context} />
|