mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a docs-only content update to the `/docs/guides/security` landing page and its neighboring guides. It adds a dedicated GDPR compliance guide, and surfaces ISO 27001 and DDoS protection coverage that Supabase already provides but wasn't listed anywhere in the docs security guide. Closes DOCS-354. ## What is the current behavior? - In `/docs/guides/security`, there is no mention of GDPR, ISO 27001 or DPA request potential, despite Supabase docs covering these partially in one place or another. - Confirmed by auditing `apps/docs/content/`: zero mentions of GDPR/data residency, zero DPA content or link to `/legal/dpa`, zero ISO 27001 mentions, and only incidental/wrong-audience mentions of DDoS protection (a pen-testing exclusion, a Storage CDN aside, a fail2ban troubleshooting article for banned users). - `regions.mdx` only frames region choice as a performance decision, with no data-residency/compliance angle. - This is a parallel docs-side counterpart to #48403 (marketing `/security` page content additions), which is adding the same GDPR/Data Residency/DPA/DDoS topics on `apps/www`. This PR does not modify `apps/www` — see that PR for the marketing-page changes. ## What is the new behavior? - New guide: `apps/docs/content/guides/security/gdpr-compliance.mdx` covering data residency (including the nuance that the "Europe" general region grouping includes non-EU jurisdictions UK and Switzerland) and the Data Processing Agreement (DPA), linked to `/legal/dpa`. - Added to the sidebar nav under Security → Compliance, alongside SOC 2 and HIPAA. - `apps/docs/content/guides/security.mdx`: added an ISO 27001 paragraph (dashboard certificate link, matching the existing SOC 2/HIPAA pattern) and a GDPR pointer paragraph to `## Compliance`; added a DDoS protection paragraph (Cloudflare CDN + fail2ban) to `## Platform configuration`. - `apps/docs/content/guides/platform/regions.mdx`: added a "Data residency" section clarifying that general region groupings may span non-matching jurisdictions, and specific regions should be used when strict jurisdictional residency is required. ## Additional context - Worktree: `~/GitHub/supabase/supabase-worktrees/nikrichers/docs-354-security-landing-page` - Note: Supabase's subprocessor list was considered for the GDPR guide but omitted — both candidate links (`/legal/customer-resources/subprocessor-list` and `/legal/privacy#subprocessors`) are not yet publishable/live. Follow up once Legal publishes that page. **Verification:** | Check | Result | | ------------------------------------ | ----------------------------------------------------------------------------------------------------- | | `pnpm lint:mdx` on changed/new files | Pass (0 errors, 0 warnings on touched files) | | `pnpm build:guides-markdown` | Fails on `master` too (unrelated missing `ai-skills.json` generated file) — not caused by this change | | Local render (`pnpm dev:docs`) | All three pages return 200; new copy, nav entry, and all links/anchors verified to resolve | ### Proof: Reviewers should believe: the security landing page and regions guide now list GDPR/ISO 27001/DDoS coverage that was previously missing, and the new GDPR guide renders correctly with working links, where before it 404'd. ### Before & After **`/docs/guides/security`** — ISO 27001, GDPR, and DDoS paragraphs now present: | [Before (production)](https://supabase.com/docs/guides/security) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security) | | ----------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | **`/docs/guides/platform/regions`** — new "Data residency" section: | [Before (production)](https://supabase.com/docs/guides/platform/regions) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/platform/regions) | | --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | |  |  | **`/docs/guides/security/gdpr-compliance`** — net-new page, no production URL exists yet (404 before this PR): | Before (production) | [After (PR preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security/gdpr-compliance) | | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | | |  | ### Test plan ```text - [ ] Visit /docs/guides/security — confirm ISO 27001, GDPR, and DDoS paragraphs render under the right headings - [ ] Visit /docs/guides/security/gdpr-compliance — confirm it renders and appears in the sidebar under Compliance (next to SOC 2, HIPAA) - [ ] Visit /docs/guides/platform/regions — confirm the new "Data residency" section renders before "General regions" - [ ] Confirm links resolve: /docs/guides/security/gdpr-compliance, /docs/guides/platform/regions#specific-regions, /legal/dpa, /dashboard/org/_/documents ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation - Added a GDPR Compliance entry to the Compliance navigation. - Updated security documentation with ISO 27001 certification details, clearer GDPR guidance, and expanded protection information. - Clarified regional data residency guidance, including primary project data and GDPR considerations. - Made minor wording and formatting improvements to the GDPR compliance guide. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Nik Richers <nik@validmind.ai>