mirror of
https://github.com/supabase/supabase.git
synced 2026-10-09 19:35:06 +03:00
## I have read the CONTRIBUTING.md file. YES ## What kind of change does this PR introduce? - docs update Closes DOCS-1080. ## What is the current behavior? - Linear item: [DOCS-1080](https://linear.app/supabase/issue/DOCS-1080/update-hipaa-and-security-docs-to-reflect-the-log-connectionsoff) (parent: PSQL-1307) - Docs do not mention that Postgres `log_connections` defaults to off for new projects, or how customers re-enable it for HIPAA/SOC 2 audit needs. - No customer-facing how-to for the Management API `log_connections` setting. ## What is the new behavior? - New guide: "Postgres connection logging" — default behavior, dashboard instructions, Management API curl examples, compliance notes. - HIPAA shared-responsibility, HIPAA projects, SOC 2, HIPAA compliance FAQ, logs guide, custom-postgres-config, and product-security updated with cross-links. - Platform nav entry added under **Platform → Postgres Connection Logging**. ### Proof: new guide and cross-links render **Verified:** `pnpm lint:mdx` (pass) · local dev (all changed pages 200) · Vercel preview (new page 200) | Check | Result | |-------|--------| | `pnpm lint:mdx` | pass (exit 0) | | Preview new guide | [200](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) | | Preview HIPAA bullet | [shared-responsibility-model#managing-healthcare-data](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) | **Quick review links:** - [Postgres connection logging — New guide for the `log_connections=off` default and re-enabling via dashboard and Management API](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) - [Shared Responsibility Model — Managing healthcare data — Added customer responsibility to keep connection logging enabled](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) - [HIPAA Projects — Added connection logging to required project configuration](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/hipaa-projects) ## Additional context - **Before ready for review:** add dashboard screenshots once FE-3666 merges; add changelog cross-link when PSQL-1307 entry is published. - CLI does not expose `log_connections`; how-to documents Management API only until dashboard screenshots are added. ### Test plan - [ ] Open [preview guide](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/platform/postgres-connection-logging) — default behavior, API examples, compliance sections present - [ ] Confirm [HIPAA shared-responsibility bullet](https://docs-git-nikrichers-docs-1080-update-hipaa-and-e3b13d-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) links to the new guide - [ ] Confirm Platform nav includes **Postgres Connection Logging** - [ ] Spot-check Management API paths against `/docs/reference/api/v1-update-postgres-config` - [ ] After FE-3666: add Database Settings screenshots to the guide and PR proof section <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Summary by CodeRabbit * **Documentation** * Added a full guide for enabling/disabling Postgres connection logging (dashboard + Management API), including verification steps and examples. * Clarified which Postgres parameters are Management API–only (CLI limitations), with `log_connections` as an example. * Updated HIPAA, SOC 2, and shared responsibility guidance to recommend keeping Postgres connection logging enabled, plus added related FAQ/resources. * Expanded telemetry logs documentation with “Logging Postgres connections” and Logs Explorer visibility notes. * **UI / Navigation** * Added the new “Postgres Connection Logging” entry to the Platform configuration navigation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
30 lines
1.9 KiB
Plaintext
30 lines
1.9 KiB
Plaintext
---
|
|
id: 'hipaa'
|
|
title: 'HIPAA Projects'
|
|
description: 'Projects that store or process Protected Health Information (PHI) and other sensitive data'
|
|
---
|
|
|
|
You can use Supabase to store and process Protected Health Information (PHI). If you want to start developing healthcare apps on Supabase, reach out to the Supabase team [here](https://forms.supabase.com/hipaa2) to sign the Business Associate Agreement (BAA).
|
|
|
|
<Admonition type="note">
|
|
|
|
Organizations must have a signed BAA with Supabase and have the Health Insurance Portability and Accountability Act (HIPAA) add-on enabled when dealing with PHI.
|
|
|
|
</Admonition>
|
|
|
|
## Configuring a HIPAA project
|
|
|
|
When the HIPAA add-on is enabled on an organization, projects within the organization can be configured as _High Compliance_. This configuration can be found in the [General Project Settings page](/dashboard/project/_/settings) of the dashboard.
|
|
Once enabled, additional security checks will be run against the project to ensure the deployed configuration is compliant. These checks are performed on a continual basis and security warnings will appear in the [Security Advisor](/dashboard/project/_/advisors/security) if a non-compliant setting is detected.
|
|
|
|
The required project configuration is outlined in the [shared responsibility model](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) for managing healthcare data.
|
|
|
|
These include:
|
|
|
|
- Enabling [Point in Time Recovery](/docs/guides/platform/backups#point-in-time-recovery) which requires at least a [small compute add-on](/docs/guides/platform/compute-add-ons).
|
|
- Turning on [SSL Enforcement](/docs/guides/platform/ssl-enforcement).
|
|
- Enabling [Network Restrictions](/docs/guides/platform/network-restrictions).
|
|
- Keeping [Postgres connection logging](/docs/guides/platform/postgres-connection-logging) enabled.
|
|
|
|
Additional security checks and controls will be added as the security advisor is extended and additional security controls are made available.
|