Files
supabase/apps/docs/content/guides/security/security-testing.mdx
T
Supun Sudaraka 6ac56da073 chore: updated the public facing docs to have the supabase.com instead of supabase.io (#45772)
### Summary

Changed the Supabase email domain in public facing docs `security.txt`
and `security-testing.mdx`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the official security contact email address across security
documentation, testing guidelines, and policy resources to ensure users,
security researchers, and developers have accurate contact information
for reporting vulnerabilities and coordinating responsible disclosure
efforts.

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45772)

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-05-11 16:22:52 +05:30

43 lines
2.7 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
id: 'security-testing'
title: 'Security testing of your Supabase projects'
description: 'Supabase provides a secure yet flexible platform. You may wish to validate the security of your own project implementation, we ask that you follow these guidelines.'
---
Supabase customer support policy for penetration testing
Customers of Supabase are permitted to carry out security assessments or penetration tests of their hosted Supabase project components. This testing may be carried out without prior approval for the customer services listed under [permitted services](#permitted-services). Supabase does not permit hosting security tooling that may be perceived as malicious or part of a campaign against Supabase customers or external services. This section is covered by the [Supabase Acceptable Use Policy](/aup) (AUP).
It is the customer’s responsibility to ensure that testing activities are aligned with this policy. Any testing performed outside of the policy will be seen as testing directly against Supabase and may be flagged as abuse behaviour. If Supabase receives an abuse report for activities related to your security testing, we will forward these to you. If you discover a security issue within any of the Supabase products, contact [Supabase Security](mailto:security@supabase.com) immediately.
Furthermore, Supabase runs a [Vulnerability Disclosure Program](https://hackerone.com/ca63b563-9661-4ac3-8d23-7581582ef451/embedded_submissions/new) (VDP) with HackerOne, and external security researchers may report any bugs found within the scope of the aforementioned program. Customer penetration testing does not form part of this VDP.
### Permitted services
- Authentication
- Database
- Edge Functions
- Storage
- Realtime
- `https://<customer_project_ref>.supabase.co/*`
- `https://db.<customer_project_ref>.supabase.co/*`
### Prohibited testing and activities
- Any activity contrary to what is listed in the AUP.
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) testing.
- Cross-tenant attacks, testing that directly targets other Supabase customers' accounts, organizations, and projects not under the customer’s control.
- Request flooding.
## Terms and conditions
The customer agrees to the following,
Security testing:
- Will be limited to the services within the customer’s project.
- Is subject to the general [Terms of Service](/terms).
- Is within the [Acceptable Usage Policy](/aup).
- Will be stopped if contacted by Supabase due to a breach of the above or a negative impact on Supabase and Supabase customers.
- Any vulnerabilities discovered directly in a Supabase product will be reported to Supabase Security within 24 hours of completion of testing.