Files
supabase/apps/www/pages/security.mdx
292c08b7b7 Added new /regions page (#49306)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature

## What is the current behavior?

Region and data residency information is split across docs, `/security`,
and legal pages.
[MARKET-1866](https://linear.app/supabase/issue/MARKET-1866/package-and-display-available-regions-better-on-website)

## What is the new behavior?

Adds `/regions`: a catalog of all 17 regions generated from
`regions.ts`, plus what stays in-region, the Europe vs EU caveat, and
links to the DPA, GDPR guide, sub-processor list, and security page.

Regions is in the footer under Security & Compliance. The security page
residency card now links here.

## Test plan

- [ ] Open `/regions` in light and dark mode
- [ ] Confirm the region count and list match
`packages/shared-data/regions.ts`
- [ ] Confirm footer Regions link and `/security` residency link go to
`/regions`


Made with [Cursor](https://cursor.com)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
  - Added a Regions page showcasing available AWS regions by geography.
- Added an interactive map and region list with selection, hover states,
keyboard accessibility, and residency badges.
- Included data residency guidance, legal resources, and a
call-to-action for next steps.
  - Added Regions links in the site footer and security documentation.

- **Documentation**
- Updated agent skill resources with expanded troubleshooting and
operational guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Francesco Sansalvadore <f.sansalvadore@gmail.com>
2026-08-27 12:45:28 +01:00

256 lines
7.8 KiB
Plaintext

import {
ClipboardCheckIcon,
CreditCardIcon,
KeyIcon,
RewindIcon,
ShieldCheckIcon,
UserGroupIcon,
} from '@heroicons/react/outline'
import SecurityNewsletterForm from '~/components/SecurityNewsletterForm'
import { Activity, FileText, Globe, Lock, Scale } from 'lucide-react'
import Layout from '../layouts/Layout'
export const meta = {
type: 'lp',
title: 'Security at Supabase',
description:
'Supabase is trusted by thousands of developers for building and deploying secure applications.',
}
export const Section = ({ children, icon, img }) => (
<div>
{icon && (
<div className="border shadow-background-surface-300 not-prose bg-surface-100 -mb-4 flex h-10 w-10 items-center justify-center rounded-full">
<figure className="w-5 h-5 flex items-center justify-center">{icon}</figure>
</div>
)}
{img && <div className="-mb-4 flex h-12 w-12 items-center justify-center">{img}</div>}
{children}
</div>
)
<div className="section-container grid grid-cols-12 items-center my-8">
<div className="col-span-12 lg:col-span-6">
<h1 className="xl:text-5xl mb-4 [&_p]:m-0">Security at Supabase</h1>
<h2 className="text-xl text-foreground-light max-w-xl m-0 [&_p]:m-0">
Supabase is trusted by thousands of developers for building and deploying secure applications.
</h2>
</div>
<div className="col-span-12 lg:col-span-5 lg:col-start-8 m-0 [&_p]:m-0">
![Supabase security](/images/security/security-hero.png)
</div>
</div>
<div className="section-container mb-16 flex flex-col gap-12">
{/* Compliance */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Compliance
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Lock strokeWidth={1} />}>
### SOC 2
Supabase is SOC 2 Type 2 compliant. This is an important security policy when [handling sensitive customer data](/docs/guides/security/soc-2-compliance).
Enterprise and Team customers can access our SOC 2 Type 2 report [on the dashboard](/dashboard/org/_/documents).
<div className="w-32">
<img src="/images/security/soc2-type2.svg" />
</div>
</Section>
<Section icon={<Activity strokeWidth={1} />}>
### HIPAA
Supabase is HIPAA compliant. You can store Protected Health Information (PHI) on our hosted platform once you enter into a Business Associate Agreement (BAA) with us and fulfill your HIPAA obligations under our [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data).
Enterprise and Team customers can request to sign our BAA [on the dashboard](/dashboard/org/_/documents).
<div className="w-32">
<img src="/images/security/HIPAA.svg" />
</div>
</Section>
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
### ISO 27001
Supabase is ISO 27001 certified. ISO 27001 is an internationally recognized standard for information security management systems (ISMS), confirming that we maintain rigorous controls to protect customer data.
Enterprise and Team customers can access our ISO 27001 certificate [on the dashboard](/dashboard/org/_/documents).
</Section>
<Section icon={<Globe strokeWidth={1} />}>
### GDPR & European Compliance
Supabase supports GDPR-compliant deployments. Projects hosted in EU regions keep your primary database data in-region, and a Data Processing Agreement (DPA) is available for customers who need a formal data processing contract under GDPR.
See how [Markprompt uses Supabase for GDPR-compliant deployments](/customers/markprompt).
</Section>
</div>
</div>
{/* Data */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Data
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<KeyIcon strokeWidth={1} />}>
### Data Encryption
All customer data is encrypted at rest with AES-256 and in transit via TLS.
Sensitive information like access tokens and keys are encrypted at the application level before they are stored in the database.
</Section>
<Section icon={<Globe strokeWidth={1} />}>
### Data Residency
When you create a project in an AWS region, your Postgres database, Auth service, and Storage objects are hosted in that region. Supabase offers regions across the US, EU, and Asia Pacific.
See the full list of [available regions](/regions).
</Section>
<Section icon={<RewindIcon strokeWidth={1} />}>
### Backups
All paid customer databases are backed up every day.
Point in Time Recovery allows restoring the database to any point in time. Customers from the Pro Plan have access to this feature as an add-on.
</Section>
<Section icon={<FileText strokeWidth={1} />}>
### Data Processing Agreement
A Data Processing Agreement (DPA) is available for customers who need a formal GDPR data processing contract. [Request or view the DPA](/legal/dpa).
</Section>
</div>
</div>
{/* Configuration */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Configuration
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Lock strokeWidth={1} />}>
### Multi-factor Authentication
Supabase allows users to enable Multi-factor authentication (MFA) on their account. MFA adds an additional layer of security to your user account, by requiring a second factor to verify your user identity.
</Section>
<Section icon={<UserGroupIcon strokeWidth={1} />}>
### Role-based access control
Members of organizations in Supabase can be granted access to specific resources.
Read more about [fine-grained access controls](/docs/guides/platform/access-control) including Read-Only and Billing-Only access.
</Section>
<Section icon={<ClipboardCheckIcon strokeWidth={1} />}>
### Vulnerability Management
Supabase works with industry experts to conduct regular penetration tests.
In addition to internal security reviews, we use various tools to scan our code for vulnerabilities including [GitHub](https://github.com), [Vanta](https://www.vanta.com/), and [DepthFirst](https://depthfirst.com/).
</Section>
<Section icon={<ShieldCheckIcon strokeWidth={1} />}>
### DDoS Protection
Supabase combats Distributed Denial of Service attacks in several ways to mitigate resource abuse and prevent runaway bills.
In addition to protection at the CDN level via Cloudflare, we employ [fail2ban](https://github.com/fail2ban/fail2ban) to prevent brute force logins. Users can [customize rate limits](/docs/guides/platform/going-into-prod#rate-limiting-resource-allocation--abuse-prevention) for critical API routes and set [spend caps](/docs/guides/platform/cost-control#spend-cap) to prevent surprise bills.
</Section>
</div>
</div>
{/* Misc */}
<div className="flex flex-col gap-4">
<h3 className="not-prose text-sm font-medium text-foreground-muted uppercase tracking-widest">
Misc
</h3>
<div className="grid grid-cols-1 md:grid-cols-2 lg:grid-cols-4 gap-8 lg:gap-16">
<Section icon={<Scale strokeWidth={1} />}>
### Shared Responsibility
Supabase secures the infrastructure. You secure your application — RLS policies, API keys, and access controls.
Read the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model).
</Section>
<Section icon={<CreditCardIcon strokeWidth={1} />}>
### Payment processing
Supabase uses [Stripe](https://stripe.com) to process payments and does not store personal credit card information for any of our customers.
Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.
</Section>
</div>
</div>
</div>
<div className="section-container mb-16">
<SecurityNewsletterForm />
</div>
export default (context) => <Layout meta={meta} children={context.children} context={context} />