Files
supabase/apps/docs/content/guides/platform/regions.mdx
Nik RichersandNik Richers c8954e6054 docs(security): add GDPR, ISO 27001, and DDoS coverage to security guide (#48449)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This is a docs-only content update to the `/docs/guides/security`
landing page and its neighboring guides. It adds a dedicated GDPR
compliance guide, and surfaces ISO 27001 and DDoS protection coverage
that Supabase already provides but wasn't listed anywhere in the docs
security guide.

Closes DOCS-354.

## What is the current behavior?

- In `/docs/guides/security`, there is no mention of GDPR, ISO 27001 or
DPA request potential, despite Supabase docs covering these partially in
one place or another.
- Confirmed by auditing `apps/docs/content/`: zero mentions of GDPR/data
residency, zero DPA content or link to `/legal/dpa`, zero ISO 27001
mentions, and only incidental/wrong-audience mentions of DDoS protection
(a pen-testing exclusion, a Storage CDN aside, a fail2ban
troubleshooting article for banned users).
- `regions.mdx` only frames region choice as a performance decision,
with no data-residency/compliance angle.
- This is a parallel docs-side counterpart to #48403 (marketing
`/security` page content additions), which is adding the same GDPR/Data
Residency/DPA/DDoS topics on `apps/www`. This PR does not modify
`apps/www` — see that PR for the marketing-page changes.

## What is the new behavior?

- New guide: `apps/docs/content/guides/security/gdpr-compliance.mdx`
covering data residency (including the nuance that the "Europe" general
region grouping includes non-EU jurisdictions UK and Switzerland) and
the Data Processing Agreement (DPA), linked to `/legal/dpa`.
- Added to the sidebar nav under Security → Compliance, alongside SOC 2
and HIPAA.
- `apps/docs/content/guides/security.mdx`: added an ISO 27001 paragraph
(dashboard certificate link, matching the existing SOC 2/HIPAA pattern)
and a GDPR pointer paragraph to `## Compliance`; added a DDoS protection
paragraph (Cloudflare CDN + fail2ban) to `## Platform configuration`.
- `apps/docs/content/guides/platform/regions.mdx`: added a "Data
residency" section clarifying that general region groupings may span
non-matching jurisdictions, and specific regions should be used when
strict jurisdictional residency is required.

## Additional context

- Worktree:
`~/GitHub/supabase/supabase-worktrees/nikrichers/docs-354-security-landing-page`
- Note: Supabase's subprocessor list was considered for the GDPR guide
but omitted — both candidate links
(`/legal/customer-resources/subprocessor-list` and
`/legal/privacy#subprocessors`) are not yet publishable/live. Follow up
once Legal publishes that page.

**Verification:**

| Check | Result |
| ------------------------------------ |
-----------------------------------------------------------------------------------------------------
|
| `pnpm lint:mdx` on changed/new files | Pass (0 errors, 0 warnings on
touched files) |
| `pnpm build:guides-markdown` | Fails on `master` too (unrelated
missing `ai-skills.json` generated file) — not caused by this change |
| Local render (`pnpm dev:docs`) | All three pages return 200; new copy,
nav entry, and all links/anchors verified to resolve |

### Proof:

Reviewers should believe: the security landing page and regions guide
now list GDPR/ISO 27001/DDoS coverage that was previously missing, and
the new GDPR guide renders correctly with working links, where before it
404'd.

### Before & After

**`/docs/guides/security`** — ISO 27001, GDPR, and DDoS paragraphs now
present:

| [Before (production)](https://supabase.com/docs/guides/security) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security)
|
|
-----------------------------------------------------------------------------------------------------------------------------------------------------
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
|
![security-before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/security-before-5fd638c1.png)
|
![security-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/security-after-2f89b1b0.png)
|

**`/docs/guides/platform/regions`** — new "Data residency" section:

| [Before
(production)](https://supabase.com/docs/guides/platform/regions) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/platform/regions)
|
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
-------------------------------------------------------------------------------------------------------------------------------------------------
|
|
![regions-before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/regions-before-e824c680.png)
|
![regions-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/regions-after-c119e50d.png)
|

**`/docs/guides/security/gdpr-compliance`** — net-new page, no
production URL exists yet (404 before this PR):

| Before (production) | [After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security/gdpr-compliance)
|
| ------------------- |
-------------------------------------------------------------------------------------------------------------------------------------------
|
| |
![gdpr-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/gdpr-after-e42cf263.png)
|

### Test plan

```text
- [ ] Visit /docs/guides/security — confirm ISO 27001, GDPR, and DDoS paragraphs render under the right headings
- [ ] Visit /docs/guides/security/gdpr-compliance — confirm it renders and appears in the sidebar under Compliance (next to SOC 2, HIPAA)
- [ ] Visit /docs/guides/platform/regions — confirm the new "Data residency" section renders before "General regions"
- [ ] Confirm links resolve: /docs/guides/security/gdpr-compliance, /docs/guides/platform/regions#specific-regions, /legal/dpa, /dashboard/org/_/documents
```

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation
- Added a GDPR Compliance entry to the Compliance navigation.
- Updated security documentation with ISO 27001 certification details,
clearer GDPR guidance, and expanded protection information.
- Clarified regional data residency guidance, including primary project
data and GDPR considerations.
- Made minor wording and formatting improvements to the GDPR compliance
guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-08-03 07:38:27 -07:00

26 lines
1.2 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: Available regions
---
Each Supabase project is deployed to one primary region. Choose the location closest to your users for the best performance.
## Data residency
The region you choose also determines where your primary project data is stored. If your data residency requirements call for data to stay within a specific jurisdiction, choose a [specific region](#specific-regions) rather than a general region grouping.
General regions deploy to _an_ available AWS region within that broader area, which may not match a specific jurisdiction. For example, the "Europe" general region includes London and Zurich, which are not EU member states. Region selection is a data-location control, not proof of regulatory compliance. For GDPR considerations, see the [GDPR compliance guide](/docs/guides/security/gdpr-compliance).
## General regions
For most projects, we recommend choosing a general region. Supabase will deploy your project to an available AWS region within that area based on current infrastructure capacity.
<SmartRegionsList />
Note: General regions aren’t yet supported for read replicas or management via the API.
## Specific regions
If you prefer, you can choose an exact AWS region for your project.
<RegionsList />