SOC 2 policies for Supabase teams

Supabase stores or processes customer data on your behalf, so it appears in the policies about access, encryption, backups, vendor risk and privacy, and in the vendor inventory those policies require.

Vendors and subprocessors · Referenced by 5 of 22 policies · Generator preset available

The 5 policies that reference Supabase

With Supabase in your intake, these policies name it in their scope, roles and procedures. The other 17 policies in the set apply to your company regardless of tooling; the template index lists all 22.

  • P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
  • P08 Encryption and Key Management Policy: Sets minimum encryption standards for data in transit and at rest and defines how cryptographic keys, secrets and certificates are generated, stored, rotated and retired.
  • P15 Backup and Recovery Policy: Requires every data set that supports the product and the business to be backed up on a defined schedule, protected, monitored and proven restorable through regular tests.
  • P16 Vendor and Third-Party Risk Management Policy: Requires vendors to be inventoried, tiered by the data and services they touch, assessed before onboarding, bound by contract, reviewed annually and offboarded cleanly.
  • P22 Privacy and Data Protection Policy: Sets out how personal data handled through the product and the business is collected, used, shared, protected, retained and made available to the people it concerns.

What the Audit Kit writes for Supabase

The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes Supabase the way you actually run it. The statements below are examples of that output for Supabase; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.

P03 Access Control Policy

Row Level Security is enabled on every table in schemas exposed through the Supabase API, policies are written per role against auth.uid() and covered by automated tests in CI, and the service_role key is used only from server-side code and stored in the secrets manager. The anon key is treated as public and grants nothing that Row Level Security does not permit.
Access to the Supabase dashboard is limited to named engineers in the Supabase organisation with multi-factor authentication enforced at the organisation level, the Owner role is limited to two named people, and Developer or Read-only roles are used for everyone else. Network restrictions limit direct Postgres connections to the production application's egress IP addresses and the engineering VPN.

P08 Encryption and Key Management Policy

Supabase encrypts project data at rest, SSL enforcement is enabled so that every Postgres connection must use TLS, database secrets that must live inside Postgres are stored with Supabase Vault, and any Restricted field is encrypted at the application layer before it is written.

P15 Backup and Recovery Policy

Point-in-Time Recovery is enabled on the production project with a seven-day recovery window in addition to the daily backups Supabase takes, a logical backup is exported weekly to company-controlled cloud storage in a second region, and a restore into a separate Supabase project is performed and documented quarterly.

P16 Vendor and Third-Party Risk Management Policy

Supabase is recorded in the vendor register as a Critical vendor and subprocessor. Its SOC 2 Type II report and data processing addendum are obtained and reviewed annually, the project region is pinned to the region agreed with customers, and the Supabase status page is subscribed to the incident channel.

P22 Privacy and Data Protection Policy

Personal data held in Supabase is inventoried by table and column in the data inventory, Supabase is listed as a subprocessor in the privacy notice, and deletion requests are executed with cascading deletes across tables and Storage buckets within 30 days and confirmed in the request ticket.

How to use this page

  1. Open the generator with the Supabase preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
  2. Download the 22 policies as Markdown. Read the sections that mention Supabase with the admin console open and fix anything that is not true of your setup.
  3. Optionally buy the Audit Kit to have sections 4 and 5 tailored to Supabase and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
  4. Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.

Other tools

Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare

Source control and CI: GitHub, GitLab

Identity providers: Google Workspace, Okta, Microsoft 365

Vendors and subprocessors: Clerk

Frequently asked questions

Does Supabase's SOC 2 report cover our own SOC 2?
No. Supabase's own SOC 2 report covers the controls Supabase operates for its platform. Your examination covers how your company configures and uses Supabase: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
What does the generator pre-fill when I arrive from this page?
The link on this page opens the generator with a preset that adds Supabase to the vendor list. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
Which policies change when I add Supabase to my answers?
5 policies name Supabase once it is in the intake: Access Control Policy, Encryption and Key Management Policy, Backup and Recovery Policy, Vendor and Third-Party Risk Management Policy, Privacy and Data Protection Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how Supabase is configured, like the examples on this page. Refunds are available within 14 days on request.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.