[{"data":1,"prerenderedAt":988},["ShallowReactive",2],{"blog-en-does-supabase-encrypt-my-data":3,"blog-index-en":633},{"id":4,"title":5,"body":6,"category":588,"cover":589,"coverAlt":590,"description":591,"draft":592,"extension":593,"faq":594,"image":610,"keywords":611,"meta":622,"navigation":623,"ogTitle":26,"path":624,"published":625,"seo":626,"stem":627,"tldr":628,"updated":625,"__hash__":632},"blog_en\u002Fblog\u002Fdoes-supabase-encrypt-my-data.md","Does Supabase encrypt my data? Yes. Here is what it stops",{"type":7,"value":8,"toc":571},"minimark",[9,13,16,19,22,27,38,45,61,79,144,148,151,154,157,160,166,170,173,176,193,197,200,209,215,224,236,240,243,246,250,259,262,266,269,272,280,299,302,306,309,318,327,331,334,448,451,455,458,469,481,486,489,493,498,534,541,545,565],[10,11,12],"p",{},"A customer emails to ask whether their data is encrypted. Or a bigger client\nsends a security questionnaire as a spreadsheet, and in it are the rows every\nquestionnaire has: encryption at rest, encryption in transit, your hosting\nprovider's SOC 2 report. Your app runs on Supabase because Lovable or Bolt set it\nup that way, and until today nobody needed you to know what any of that means.",[10,14,15],{},"So, does Supabase encrypt your data? Yes. All of it, on every plan, and the\ncertificates behind the claim are real.",[10,17,18],{},"Where most answers go wrong is in stopping there, as though encryption decided\nwho gets to read your data. It decides something narrower. Think of Supabase as\na bank. Encryption at rest is the vault, encryption in transit is the armoured\nvan, and SOC 2 is the inspector who checks that both are run the way the bank\nsays. Every one of them is about somebody who was never meant to be inside. The\nrule at the counter, about whose statement a customer may ask for, is a separate\nthing, and your project is where it gets written.",[10,20,21],{},"Every figure below was read off Supabase's pages and documentation on 29\nSeptember 2026.",[23,24,26],"h2",{"id":25},"does-supabase-encrypt-my-data","Does Supabase encrypt my data?",[10,28,29,30,37],{},"Yes. Supabase's ",[31,32,36],"a",{"href":33,"rel":34},"https:\u002F\u002Fsupabase.com\u002Fsecurity",[35],"nofollow","security page"," states that all\ncustomer data is encrypted at rest with AES-256 and in transit with TLS, and\nthere is nothing for you to switch on.",[10,39,40,44],{},[41,42,43],"strong",{},"At rest"," means on the disks. Your database is written to storage in encrypted\nform, so a copy of the disk taken away from Supabase's machines is unreadable on\nits own.",[10,46,47,50,51,56,57,60],{},[41,48,49],{},"In transit"," means on the way between your visitor and Supabase. Your app\ntalks to Supabase through its web APIs, for data, sign-ins and files, and\nSupabase's\n",[31,52,55],{"href":53,"rel":54},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fssl-enforcement",[35],"SSL enforcement guide","\nsays every one of those APIs refuses an unencrypted connection. The exception is\na direct connection to the Postgres database underneath, the kind a backup tool\nor a server of your own might open. Those accept an unencrypted connection until\nyou turn on ",[41,58,59],{},"Enforce SSL on incoming connections"," under Database Settings. Your\nvisitors' browsers never open one.",[10,62,63,66,67,72,73,78],{},[41,64,65],{},"Column encryption"," is the one layer that stays off. It keeps a single value,\na phone number say, scrambled even inside the database. Supabase used to\ndocument a way to do it, and its\n",[31,68,71],{"href":69,"rel":70},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fdatabase\u002Fextensions\u002Fpgsodium",[35],"pgsodium page","\nnow recommends against that feature, citing its operational complexity and the\nrisk of misconfiguring it, and adds that encryption at rest is likely enough for\nSOC 2 and HIPAA. For secrets such as a third-party API key there is\n",[31,74,77],{"href":75,"rel":76},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fdatabase\u002Fvault",[35],"Vault",", which stores them\nencrypted and hands them back through a view.",[80,81,82,98],"table",{},[83,84,85],"thead",{},[86,87,88,92,95],"tr",{},[89,90,91],"th",{},"Layer",[89,93,94],{},"On by default",[89,96,97],{},"What it protects against",[99,100,101,113,124,134],"tbody",{},[86,102,103,107,110],{},[104,105,106],"td",{},"At rest, AES-256",[104,108,109],{},"Yes, on every plan",[104,111,112],{},"A copy of the disk read without going through Supabase",[86,114,115,118,121],{},[104,116,117],{},"In transit, TLS",[104,119,120],{},"Yes on every API. On direct Postgres, once you enforce it",[104,122,123],{},"Somebody reading the traffic between an app and Supabase",[86,125,126,128,131],{},[104,127,65],{},[104,129,130],{},"No, and Supabase advises against the feature it used to offer",[104,132,133],{},"A single value read by someone who can query its table",[86,135,136,138,141],{},[104,137,77],{},[104,139,140],{},"For each secret you store in it",[104,142,143],{},"A secret sitting readable on disk or in a backup file",[23,145,147],{"id":146},"what-does-supabases-encryption-stop","What does Supabase's encryption stop?",[10,149,150],{},"Anyone who reaches your data without asking the database for it. Somebody who\nwalks off with a disk, copies a backup file, or listens in on the traffic\nbetween a browser and Supabase gets scrambled bytes and nothing else.",[10,152,153],{},"A request the database decides to answer is another matter. Encryption at rest\nworks underneath Postgres, so the database reads its own files as plain data,\nfor every query it serves. Which queries it serves is settled by the permissions\non each table. In Supabase that is Row Level Security, the rule saying which\nrows each visitor may read, and each table needs it switched on with a rule\nwritten for it.",[10,155,156],{},"That is the counter in the bank. The vault opens for the teller every time,\nbecause the teller works for the bank. If nobody wrote down whose statements a\ncustomer may see, the teller hands over whatever is asked for, and the armoured\nvan delivers it, sealed all the way, to whoever asked.",[10,158,159],{},"Supabase's documentation says the same about Vault, which does encrypt values\ninside the database: \"anyone that has access to the view has access to\ndecrypted secrets.\"",[161,162],"diagram",{"alt":163,"caption":164,"src":165},"Three routes out of the same padlocked database. A drive carried away and a padlocked wire each deliver only scrambled blocks to a magnifying glass. A browser that sends a request with the anon key gets the rows back through a padlocked channel, and they arrive readable.","Encryption stops the first two routes. The third is a question the database answers, and it decrypts to answer it.","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fwhat-encryption-stops-1600x720.png",[23,167,169],{"id":168},"does-encryption-stop-a-stranger-reading-my-tables","Does encryption stop a stranger reading my tables?",[10,171,172],{},"No, and we measured how often that matters. In August 2026 we scanned 30,998\nlive apps built with Lovable, Base44, Replit, v0 and Bolt. In 3,680 of them we\ncould complete the check that asks a Supabase database, with no login, whether a\ntable will hand over its rows. In 2,096 of them, 57%, at least one table would,\nand 394 of those had an open table named after people: users, profiles,\ncustomers, orders.",[10,174,175],{},"Every one of those databases was encrypted at rest the whole time, by the\nplatform's own account of how it runs, and any stranger who asked would have\nbeen sent the rows over TLS. Nothing about the encryption failed, and it played\nno part in deciding who got an answer.",[10,177,178,179,183,184,187,188,192],{},"The request itself is ordinary. It is the one your own app makes to show a\nsigned-in customer their orders, sent without the sign-in: the public key that\nis meant to be in your page, and a ",[180,181,182],"code",{},"GET"," to ",[180,185,186],{},"\u002Frest\u002Fv1\u002F"," with a table name on the\nend. Our scan read how many rows each table would return and stopped there,\nwithout fetching one.\n",[31,189,191],{"href":190},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","The full measurement"," sets out\nwhat that 57% is a share of and how much we could not see.",[23,194,196],{"id":195},"is-supabase-soc-2-compliant","Is Supabase SOC 2 compliant?",[10,198,199],{},"Yes. Supabase holds a SOC 2 Type 2 report from an independent auditor, renewed\nevery year.",[10,201,202,203,208],{},"A SOC 2 report is an auditor's account of whether a company's security controls\nworked the way the company says they do. Type 2 means they were tested across a\nwhole period, and Supabase's runs from 1 March to 28 February. It covers\nsecurity, availability, processing integrity, confidentiality and privacy,\nacross the database, Storage, Auth, Realtime, Edge Functions and the Data API,\nand Supabase's\n",[31,204,207],{"href":205,"rel":206},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fsecurity\u002Fsoc-2-compliance",[35],"SOC 2 page"," marks\nwhere it ends:",[210,211,212],"blockquote",{},[10,213,214],{},"Supabase's SOC 2 compliance does not transfer to environments outside of the\nSupabase product or Supabase's control.",[10,216,217,218,223],{},"In the bank, that is the inspector's report on the vault and the vans. Your\ntable rules sit outside it, because you write them: Supabase's\n",[31,219,222],{"href":220,"rel":221},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fdeployment\u002Fshared-responsibility-model",[35],"shared responsibility model","\nlists access management and applying security controls among the things a\ncustomer is always responsible for.",[10,225,226,227,230,231,235],{},"Two more things follow from that. If a client needs ",[41,228,229],{},"your"," company to be SOC 2\ncompliant, Supabase's SOC 2 page says a customer in that position has to put\nthe controls in place and go through an audit of its own. And whether Supabase is a\nsound platform to build on at all is\n",[31,232,234],{"href":233},"\u002Fblog\u002Fis-supabase-secure","a separate question with its own article",".",[23,237,239],{"id":238},"how-do-i-get-supabases-soc-2-report","How do I get Supabase's SOC 2 report?",[10,241,242],{},"From your organization's dashboard, on the Team plan or above. It sits under\nLegal Documents, next to the ISO 27001 certificate and Supabase's standard\nsecurity questionnaire, and an organization on Free or Pro finds an upgrade\nbutton there instead.",[10,244,245],{},"Team starts at $599 a month, where Pro starts at $25, so it helps to know what\nthe difference buys. Supabase's documentation says every project is governed by\nthe same set of compliance controls, so a project on Pro runs on the same\naudited platform. Team adds the documents, along with single sign-on for the\ndashboard, daily backups kept for 14 days where Pro keeps 7, and eligibility for\nHIPAA. If a client asks for the report itself, ask whether Supabase's public\nsecurity page will do before you change plans for one PDF.",[23,247,249],{"id":248},"is-supabase-iso-27001-certified","Is Supabase ISO 27001 certified?",[10,251,252,253,258],{},"Yes, to ISO\u002FIEC 27001:2022, which Supabase\n",[31,254,257],{"href":255,"rel":256},"https:\u002F\u002Fsupabase.com\u002Fblog\u002Fsupabase-is-now-iso-27001-certified",[35],"announced"," on 22\nApril 2026.",[10,260,261],{},"ISO 27001 certifies a management system: the policies, risk assessments and\nprocesses a company uses to look after the information it holds. An accredited\nauditor issues the certificate for three years and comes back every year in\nbetween to check the system is still running. In the bank, it is the inspector\nreviewing how the security procedures get decided and kept up to date. Supabase's\nannouncement describes SOC 2 as widely accepted in North America and ISO 27001\nas widely accepted in Europe, Asia and the public sector. The certificate is in\nthe same Legal Documents section, on the same plans.",[23,263,265],{"id":264},"is-supabase-hipaa-compliant","Is Supabase HIPAA compliant?",[10,267,268],{},"It can be for your project, once you sign a Business Associate Agreement with\nSupabase and pay for its HIPAA add-on. It is not automatic, and Supabase's SOC 2\npage says SOC 2 does not stand in for it.",[10,270,271],{},"A Business Associate Agreement, or BAA, is the written contract US health law\nrequires before a company may handle protected health information on your\nbehalf. Supabase signs one on the Team plan or above. The add-on has no\npublished price: you send a request, Supabase replies with the price and the\nprocess, and a Free or Pro organization that applies still has to move to Team\nonce it is approved.",[10,273,274,275,279],{},"Signing is where your part starts. Supabase's\n",[31,276,222],{"href":277,"rel":278},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fdeployment\u002Fshared-responsibility-model#managing-healthcare-data",[35],"\nlists what a HIPAA customer has to do, and these are the items an app owner is\nleast likely to have met:",[281,282,283,287,290,293,296],"ul",{},[284,285,286],"li",{},"Mark the project as a HIPAA project, and act on what the Security Advisor\nraises about it.",[284,288,289],{},"Turn on two-factor sign-in for every account in the Supabase organization.",[284,291,292],{},"Turn on point-in-time recovery, which needs at least the Small compute add-on.",[284,294,295],{},"Turn on SSL enforcement and network restrictions.",[284,297,298],{},"Keep health data out of public storage buckets.",[10,300,301],{},"Encryption at rest and in transit is on that list as well, and it is the one\nitem Supabase has already done.",[23,303,305],{"id":304},"is-supabase-gdpr-compliant","Is Supabase GDPR compliant?",[10,307,308],{},"Supabase supports GDPR-compliant apps and supplies the two pieces only it can.\nWhether your app complies depends on what it does with people's data.",[10,310,311,312,317],{},"The first piece is location. You pick a region when you create a project, and a\nspecific EU region keeps your database, Auth and Storage there. Choose the\nregion by name, because Supabase's general Europe option also includes London\nand Zurich. The second is the\n",[31,313,316],{"href":314,"rel":315},"https:\u002F\u002Fsupabase.com\u002Flegal\u002Fdpa",[35],"Data Processing Addendum",", the contract GDPR\nrequires between you and a company processing personal data for you. Supabase's\nforms part of its Terms of Service, so every organization already has one.",[10,319,320,321,326],{},"The rest belongs to your app: why you collect each field, how people agree to\nit, who can read it and how you delete it when asked. Supabase's\n",[31,322,325],{"href":323,"rel":324},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fsecurity\u002Fgdpr-compliance",[35],"GDPR page"," says\noutright that picking a region does not make an application compliant on its\nown. What your app owes under the law is a question for a lawyer.",[23,328,330],{"id":329},"how-do-i-answer-a-clients-security-questionnaire","How do I answer a client's security questionnaire?",[10,332,333],{},"Split it into two piles before you write anything. Some rows ask about\nSupabase's platform and are answered from Supabase's documents. The others ask\nabout your project, and you are the only person who can answer them.",[80,335,336,349],{},[83,337,338],{},[86,339,340,343,346],{},[89,341,342],{},"The questionnaire asks",[89,344,345],{},"Who answers",[89,347,348],{},"Where the answer is",[99,350,351,362,372,382,392,403,418,428,438],{},[86,352,353,356,359],{},[104,354,355],{},"Is data encrypted at rest?",[104,357,358],{},"Supabase",[104,360,361],{},"AES-256, on Supabase's security page",[86,363,364,367,369],{},[104,365,366],{},"Is data encrypted in transit?",[104,368,358],{},[104,370,371],{},"TLS on every API, and on direct Postgres connections once you enforce SSL",[86,373,374,377,379],{},[104,375,376],{},"Does your provider hold SOC 2 or ISO 27001?",[104,378,358],{},[104,380,381],{},"Both, with the documents downloadable on Team or Enterprise",[86,383,384,387,389],{},[104,385,386],{},"Do you have a DPA with your processors?",[104,388,358],{},[104,390,391],{},"Part of Supabase's Terms of Service",[86,393,394,397,400],{},[104,395,396],{},"Where is the data stored?",[104,398,399],{},"You",[104,401,402],{},"The region you picked when you created the project",[86,404,405,408,411],{},[104,406,407],{},"How often is the data backed up?",[104,409,410],{},"Your plan",[104,412,413,414],{},"Nothing automatic on Free, daily on Pro. ",[31,415,417],{"href":416},"\u002Fblog\u002Fsupabase-free-plan-limits","What each plan keeps",[86,419,420,423,425],{},[104,421,422],{},"Who can read which records?",[104,424,399],{},[104,426,427],{},"The Row Level Security policy on each table",[86,429,430,433,435],{},[104,431,432],{},"Where are credentials kept?",[104,434,399],{},[104,436,437],{},"The secret key on a server only. The publishable key is designed to be public",[86,439,440,443,445],{},[104,441,442],{},"Who has administrative access?",[104,444,399],{},[104,446,447],{},"The members of your Supabase organization, with two-factor on",[10,449,450],{},"The Supabase rows copy straight across from its documents. The last three are\nthe ones the client sent the questionnaire to find out, and answering them needs\nyour own project open in front of you.",[23,452,454],{"id":453},"what-do-i-tell-a-client-who-asks-who-can-read-the-data","What do I tell a client who asks who can read the data?",[10,456,457],{},"The state of your policies, table by table, and the date you last checked them.\n\"The data is encrypted\" answers a question about stolen disks, and a client\nasking about access is asking about the counter.",[10,459,460,461,464,465,468],{},"A straight answer names the tables that hold personal data and says each has\nRow Level Security switched on, with a policy tying every row to the signed-in\nperson it belongs to. It says when you last checked from outside, as a visitor\nwith no login, that those tables returned nothing. If a table is public on\npurpose, a product list or published posts, it says that too. Then the admin\nside: who can open your Supabase dashboard, with two-factor on, and where the\nsecret key lives. That key is ",[180,462,463],{},"service_role"," in older projects and ",[180,466,467],{},"sb_secret_…","\nin newer ones, and it belongs on a server.",[10,470,471,472,476,477,235],{},"To find the state of your tables, start with the Security Advisor in your\nSupabase dashboard, which lists every table with Row Level Security switched\noff. A table can pass that and still be open, through a policy that lets\neveryone in.\n",[31,473,475],{"href":474},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","The four states a table can be in","\nshows how to tell them apart, and there is a plain-language walkthrough for\n",[31,478,480],{"href":479},"\u002Fis-your-supabase-app-safe","Supabase apps",[161,482],{"alt":483,"caption":484,"src":485},"The same anonymous request, marked anon, sent to two tables that carry an identical padlock. One table has a policy barrier in front of it and returns nothing. The other has none and returns every row.","Both tables are encrypted in exactly the same way. The policy is the only difference between the two answers.","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fsame-lock-two-answers-1600x680.png",[10,487,488],{},"Write down only what you have checked. If you have not read a table's policy\nyet, give the date by which you will.",[23,490,492],{"id":491},"how-reeve-checks-the-answer-from-outside","How Reeve checks the answer from outside",[10,494,495],{},[41,496,497],{},"The rows a questionnaire leaves to you are about who gets an answer. Reeve\nasks your live app the way a stranger would and tells you which tables\nanswered.",[281,499,500,510,516],{},[284,501,502,505,506,235],{},[41,503,504],{},"The free scan"," asks every table your app names how many rows a visitor\nwith no login would get, reads the count and stops without fetching a row.\nAbout 20 seconds, no account: ",[31,507,509],{"href":508},"\u002Fsecurity-scanner","scan your app",[284,511,512,515],{},[41,513,514],{},"Reeve Monitor"," re-runs all nine checks every hour on up to three apps and\nemails you the day your grade gets worse, so a table your builder adds after\nthe questionnaire went back is checked within the hour.",[284,517,518,521,522,524,525,529,530,235],{},[41,519,520],{},"Care"," runs the same checks and keeps a copy of your ",[41,523,358],{}," database\noutside your Supabase account, taken on a schedule and read back before it\ncounts, which answers the backup row. Each copy is encrypted with AES-256-GCM\nunder a key that belongs to your account alone, and\n",[31,526,528],{"href":527},"\u002Flegal","our legal page"," explains how those keys are kept.\n",[31,531,533],{"href":532},"\u002Fsupabase-backups","How a copy is taken and put back",[10,535,536,537,235],{},"What each plan covers and costs is on the ",[31,538,540],{"href":539},"\u002Fpricing","pricing page",[23,542,544],{"id":543},"what-to-do-now","What to do now",[546,547,548],"key-takeaways",{},[281,549,550,553,556,559,562],{},[284,551,552],{},"Answer the encryption rows from Supabase's security page: AES-256 at rest and TLS in transit, on every plan, with nothing to turn on.",[284,554,555],{},"If a client needs the SOC 2 report or the ISO 27001 certificate itself, that means the Team plan. Download both from Legal Documents in your organization dashboard.",[284,557,558],{},"If your app holds health data, sign the BAA and work through Supabase's HIPAA list before any of it goes in.",[284,560,561],{},"Answer the access rows from your own project. Open the Security Advisor, then read the policy on every table that holds people.",[284,563,564],{},"Check the result from outside, as a visitor with no login, and put the date next to your answer.",[10,566,567,568,570],{},"The encryption half of the questionnaire is already answered for you. Before you\nsend it back, ",[31,569,509],{"href":508}," and see which of your tables\nanswers a stranger today.",{"title":572,"searchDepth":573,"depth":573,"links":574},"",3,[575,577,578,579,580,581,582,583,584,585,586,587],{"id":25,"depth":576,"text":26},2,{"id":146,"depth":576,"text":147},{"id":168,"depth":576,"text":169},{"id":195,"depth":576,"text":196},{"id":238,"depth":576,"text":239},{"id":248,"depth":576,"text":249},{"id":264,"depth":576,"text":265},{"id":304,"depth":576,"text":305},{"id":329,"depth":576,"text":330},{"id":453,"depth":576,"text":454},{"id":491,"depth":576,"text":492},{"id":543,"depth":576,"text":544},"Security basics","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcover-1200x630.png","A round vault door, shut and bolted, lit in teal. Beside it a counter hatch stands open, and a sheet of paper is sliding out of it.","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.",false,"md",[595,598,600,602,604,607],{"q":596,"a":597},"Does Supabase encrypt my data at rest?","Yes. Supabase encrypts all customer data at rest with AES-256 and in transit with TLS, on every plan, with nothing for you to switch on. What it does not add by default is a second layer on individual columns inside the database, and Supabase now advises against the column encryption feature it used to document. For secrets such as a third-party API key it offers Vault.",{"q":196,"a":599},"Yes. Supabase holds a SOC 2 Type 2 report from an independent auditor, renewed every year over an audit period that runs from 1 March to 28 February. It covers the Supabase platform. Supabase states that the compliance does not transfer outside its product, and the settings inside your own project, such as who can read each table, stay your responsibility.",{"q":239,"a":601},"Download it from Legal Documents in your organization dashboard. It is available to organizations on the Team plan, from $599 a month, and on Enterprise. The ISO 27001 certificate and a standard security questionnaire sit in the same place. On Free or Pro that page offers an upgrade instead.",{"q":265,"a":603},"It can be for your project, and it is not automatic. You need a signed Business Associate Agreement and the paid HIPAA add-on, both on the Team plan or above, and Supabase says SOC 2 is no substitute for either. Then you mark the project as a HIPAA project and switch on what Supabase lists for it, including two-factor sign-in, point-in-time recovery, SSL enforcement and network restrictions.",{"q":605,"a":606},"Does encryption protect me from a misconfigured table?","No. Encryption protects data from someone who gets at the disk or the traffic without going through the database. A request the database decides to answer is decrypted for whoever sent it, and which requests get answered is set by Row Level Security on each table. In August 2026 we found at least one table open to a stranger in 2,096 of the 3,680 Supabase apps we could check.",{"q":608,"a":609},"What do I tell a client who asks if their data is encrypted?","Yes, with the detail: AES-256 at rest and TLS in transit, applied by Supabase to every project, with a SOC 2 Type 2 report and ISO 27001 certification behind it. Then answer the question underneath, which is who can read it. Name the tables holding personal data, the Row Level Security policy on each, and the date you last checked from outside that a visitor with no login gets nothing back.","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",[612,613,614,615,616,617,618,619,620,621],"does supabase encrypt data","supabase encryption at rest","is supabase data encrypted","supabase soc 2 report","is supabase soc 2 compliant","supabase iso 27001","supabase hipaa","is supabase gdpr compliant","supabase compliance","supabase security certifications",{},true,"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","2026-09-30",{"title":5,"description":591},"blog\u002Fdoes-supabase-encrypt-my-data",[629,630,631],"Does Supabase encrypt data? Yes. Every project is encrypted at rest with AES-256 and in transit with TLS, on every plan, with nothing to switch on.","Supabase also holds a SOC 2 Type 2 report and an ISO 27001 certificate. You can download both on the Team plan and above, and HIPAA needs a signed agreement on top.","None of it decides who the database answers. In 2,096 of the 3,680 Supabase apps we could check, a table would hand its rows to a stranger with no login.","apIqgyXZ71-BjnmfOzeTE9nOK8FRSBGTf3N6S-vXCMw",[634,640,646,652,658,664,670,676,682,688,694,700,701,706,713,719,725,730,736,742,748,754,760,766,772,778,784,790,796,802,808,814,820,826,832,838,844,850,856,862,868,874,880,886,892,897,903,909,915,921,927,933,939,945,950,955,961,967,972,977,983],{"path":635,"title":636,"description":637,"published":638,"category":588,"image":639,"draft":592},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":588,"image":645,"draft":592},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":647,"title":648,"description":649,"published":650,"category":588,"image":651,"draft":592},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":653,"title":654,"description":655,"published":656,"category":588,"image":657,"draft":592},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":659,"title":660,"description":661,"published":662,"category":588,"image":663,"draft":592},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":665,"title":666,"description":667,"published":668,"category":588,"image":669,"draft":592},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":671,"title":672,"description":673,"published":674,"category":588,"image":675,"draft":592},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":677,"title":678,"description":679,"published":680,"category":588,"image":681,"draft":592},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":683,"title":684,"description":685,"published":686,"category":588,"image":687,"draft":592},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":689,"title":690,"description":691,"published":692,"category":588,"image":693,"draft":592},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":695,"title":696,"description":697,"published":698,"category":588,"image":699,"draft":592},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":624,"title":5,"description":591,"published":625,"category":588,"image":610,"draft":592},{"path":416,"title":702,"description":703,"published":704,"category":588,"image":705,"draft":592},"Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":707,"title":708,"description":709,"published":710,"category":711,"image":712,"draft":592},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":714,"title":715,"description":716,"published":717,"category":711,"image":718,"draft":592},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":720,"title":721,"description":722,"published":723,"category":711,"image":724,"draft":592},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":726,"title":727,"description":728,"published":723,"category":588,"image":729,"draft":592},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":731,"title":732,"description":733,"published":734,"category":588,"image":735,"draft":592},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":737,"title":738,"description":739,"published":740,"category":588,"image":741,"draft":592},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":743,"title":744,"description":745,"published":746,"category":711,"image":747,"draft":592},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":749,"title":750,"description":751,"published":752,"category":588,"image":753,"draft":592},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":755,"title":756,"description":757,"published":758,"category":588,"image":759,"draft":592},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":761,"title":762,"description":763,"published":764,"category":588,"image":765,"draft":592},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":767,"title":768,"description":769,"published":770,"category":588,"image":771,"draft":592},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":773,"title":774,"description":775,"published":776,"category":588,"image":777,"draft":592},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":779,"title":780,"description":781,"published":782,"category":588,"image":783,"draft":592},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":785,"title":786,"description":787,"published":788,"category":588,"image":789,"draft":592},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":791,"title":792,"description":793,"published":794,"category":588,"image":795,"draft":592},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":797,"title":798,"description":799,"published":800,"category":711,"image":801,"draft":592},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":803,"title":804,"description":805,"published":806,"category":711,"image":807,"draft":592},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":809,"title":810,"description":811,"published":812,"category":711,"image":813,"draft":592},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":815,"title":816,"description":817,"published":818,"category":588,"image":819,"draft":592},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":821,"title":822,"description":823,"published":824,"category":588,"image":825,"draft":592},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":827,"title":828,"description":829,"published":830,"category":588,"image":831,"draft":592},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":833,"title":834,"description":835,"published":836,"category":588,"image":837,"draft":592},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":839,"title":840,"description":841,"published":842,"category":588,"image":843,"draft":592},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":845,"title":846,"description":847,"published":848,"category":588,"image":849,"draft":592},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":851,"title":852,"description":853,"published":854,"category":588,"image":855,"draft":592},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":857,"title":858,"description":859,"published":860,"category":588,"image":861,"draft":592},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":863,"title":864,"description":865,"published":866,"category":588,"image":867,"draft":592},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":869,"title":870,"description":871,"published":872,"category":588,"image":873,"draft":592},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":875,"title":876,"description":877,"published":878,"category":711,"image":879,"draft":592},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":881,"title":882,"description":883,"published":884,"category":588,"image":885,"draft":592},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":887,"title":888,"description":889,"published":890,"category":711,"image":891,"draft":592},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":233,"title":893,"description":894,"published":895,"category":588,"image":896,"draft":592},"Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":898,"title":899,"description":900,"published":901,"category":588,"image":902,"draft":592},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":904,"title":905,"description":906,"published":907,"category":588,"image":908,"draft":592},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":910,"title":911,"description":912,"published":913,"category":588,"image":914,"draft":592},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":916,"title":917,"description":918,"published":919,"category":711,"image":920,"draft":592},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":922,"title":923,"description":924,"published":925,"category":711,"image":926,"draft":592},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":928,"title":929,"description":930,"published":931,"category":588,"image":932,"draft":592},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":934,"title":935,"description":936,"published":937,"category":588,"image":938,"draft":592},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":940,"title":941,"description":942,"published":943,"category":711,"image":944,"draft":592},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":190,"title":946,"description":947,"published":948,"category":588,"image":949,"draft":592},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":951,"title":952,"description":953,"published":948,"category":588,"image":954,"draft":592},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":956,"title":957,"description":958,"published":959,"category":588,"image":960,"draft":592},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":962,"title":963,"description":964,"published":965,"category":711,"image":966,"draft":592},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":474,"title":968,"description":969,"published":970,"category":588,"image":971,"draft":592},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":973,"title":974,"description":975,"published":970,"category":711,"image":976,"draft":592},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":978,"title":979,"description":980,"published":981,"category":711,"image":982,"draft":592},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":984,"title":985,"description":986,"published":981,"category":588,"image":987,"draft":592},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]