[{"data":1,"prerenderedAt":653},["ShallowReactive",2],{"blog-en-is-supabase-secure":3,"blog-index-en":411},{"id":4,"title":5,"body":6,"category":367,"cover":368,"coverAlt":369,"description":370,"draft":371,"extension":372,"faq":373,"image":391,"keywords":392,"meta":400,"navigation":401,"ogTitle":25,"path":402,"published":403,"seo":404,"stem":405,"tldr":406,"updated":403,"__hash__":410},"blog_en\u002Fblog\u002Fis-supabase-secure.md","Is Supabase secure? Yes. Your project is a separate question",{"type":7,"value":8,"toc":355},"minimark",[9,13,21,26,29,40,43,46,50,53,59,68,71,77,80,84,87,90,93,101,108,112,115,235,238,242,245,251,262,272,277,287,291,313,325,332,336,339,342,345,348],[10,11,12],"p",{},"Somebody told you Supabase is not safe for real user data. Somebody else told\nyou it runs half the apps you have heard of this year. Both of them were\nconfident, and neither of them had opened your app.",[10,14,15,16,20],{},"Here is the part that guide after guide gets wrong: ",[17,18,19],"strong",{},"\"is Supabase secure\" and\n\"is my Supabase project secure\" get answered by two different people."," Supabase\nanswers the first one, and answers it well. The second one is yours, whether or\nnot anybody mentioned it had been handed over.",[22,23,25],"h2",{"id":24},"is-supabase-secure","Is Supabase secure?",[10,27,28],{},"Yes. Outside auditors have examined the platform, and its certifications are a\nmatter of record.",[10,30,31,32,39],{},"Supabase is SOC 2 Type 2 compliant and ISO 27001 certified. Customer data is\nencrypted at rest with AES-256 and in transit with TLS. There is a HIPAA\noffering for health data, which needs an add-on and a signed agreement. They run\nregular penetration tests with outside experts, and they publish all of it on\n",[33,34,38],"a",{"href":35,"rel":36},"https:\u002F\u002Fsupabase.com\u002Fsecurity",[37],"nofollow","their security page",".",[10,41,42],{},"Think of it as a building. The foundations are sound, the fire doors work, the\nentrance has a guard on it, and there is a certificate on the wall from somebody\nwho came and inspected the place. That is genuinely what you are buying.",[10,44,45],{},"Your project is a flat inside that building.",[22,47,49],{"id":48},"what-does-that-certificate-actually-cover","What does that certificate actually cover?",[10,51,52],{},"The building. Supabase writes the boundary down in one sentence, in their own\nSOC 2 documentation:",[54,55,56],"blockquote",{},[10,57,58],{},"Supabase's SOC 2 compliance does not transfer to environments outside of the\nSupabase product or Supabase's control.",[10,60,61,62,67],{},"The same page adds that data on the customer side of that boundary is the\ncustomer's responsibility, and their\n",[33,63,66],{"href":64,"rel":65},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fdeployment\u002Fshared-responsibility-model",[37],"shared responsibility model","\nsets out which side is which. Supabase runs the infrastructure, the operating\nsystem, the Postgres upgrades and the platform's own monitoring. Your side holds\nyour account and who has access to it, your data, your database secrets and API\nkeys, and Row Level Security, which the page recommends you always apply.",[10,69,70],{},"That last item is the whole of this article. Row Level Security is the rule on\neach table saying who may read which rows. It stays off until somebody turns it\non, and turning it on happens inside your project, on a page you may never have\nopened.",[72,73],"diagram",{"alt":74,"caption":75,"src":76},"Two nested enclosures. The outer wall is solid, ticked, and carries a SOC 2 plaque; a request passes through its guarded gate. The inner wall, labelled RLS, has a gap in it, and the request continues through the gap to a stack of database rows.","The outer wall is inspected and certified. The request that reaches your rows came through a gap in the wall inside it, which is the one your project draws.","\u002Fblog\u002Fis-supabase-secure\u002Fwhere-the-certificate-stops-1600x760.png",[10,78,79],{},"The certificate is for the building. The one thing the platform does about the\nflats is point at the doors: the Security Advisor in your dashboard names every\ntable with the rule switched off, and leaves the decision with you.",[22,81,83],{"id":82},"then-why-do-so-many-supabase-apps-leak-data","Then why do so many Supabase apps leak data?",[10,85,86],{},"Because everything on your side of that line goes on working perfectly while it\nsits wide open.",[10,88,89],{},"In August 2026 we scanned 30,998 live apps built with Lovable, Base44, Replit,\nv0 and Bolt. In 3,680 of them we could complete the check that asks a database,\ncarrying no login at all, whether it will hand over rows. 2,096 said yes to at\nleast one table. Storage told the same story from a different angle: of the\n27,269 apps where we could check, 792 had a bucket a stranger could list.",[10,91,92],{},"None of that was a Supabase failure. Every one of those answers came from a\npatched, encrypted database on a certified platform, doing exactly what its own\nproject had told it to do. The building was fine. The doors inside it were open.",[10,94,95,96,100],{},"It happens because of the order things get built in. Your app works from the\nfirst day, and it works whether the rules are written or not, so there is no\nmoment where anything goes wrong and prompts you to look. The\n",[33,97,99],{"href":98},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","full measurement"," sets out how\nmuch of that we could see and how much we could not.",[10,102,103,104,39],{},"If you want the answer for your own app instead of for the platform, our free\nscan makes the same anonymous request from outside and reports which of your\ntables answered. About 20 seconds, no account: ",[33,105,107],{"href":106},"\u002F#scan","scan your app",[22,109,111],{"id":110},"is-supabase-safe-for-production","Is Supabase safe for production?",[10,113,114],{},"Yes, and what you have to do about it is short, because Supabase already did the\nlong half.",[116,117,118,134],"table",{},[119,120,121],"thead",{},[122,123,124,128,131],"tr",{},[125,126,127],"th",{},"Concern",[125,129,130],{},"Who handles it",[125,132,133],{},"What it means for you",[135,136,137,149,158,167,177,190,211,223],"tbody",{},[122,138,139,143,146],{},[140,141,142],"td",{},"Server patching, Postgres upgrades, the OS",[140,144,145],{},"Supabase",[140,147,148],{},"Nothing to do",[122,150,151,154,156],{},[140,152,153],{},"Encryption at rest and in transit",[140,155,145],{},[140,157,148],{},[122,159,160,163,165],{},[140,161,162],{},"Physical security, network security, pen tests",[140,164,145],{},[140,166,148],{},[122,168,169,172,174],{},[140,170,171],{},"Backups of your database",[140,173,145],{},[140,175,176],{},"Daily on a paid plan, and absent on the free one. Check which you are on",[122,178,179,182,187],{},[140,180,181],{},"Which rows a visitor is allowed to read",[140,183,184],{},[17,185,186],{},"You",[140,188,189],{},"A Row Level Security policy on every table holding real data",[122,191,192,195,199],{},[140,193,194],{},"Which key went into your app",[140,196,197],{},[17,198,186],{},[140,200,201,202,206,207,210],{},"The publishable key belongs there. ",[203,204,205],"code",{},"service_role"," and ",[203,208,209],{},"sb_secret_"," never do",[122,212,213,216,220],{},[140,214,215],{},"Which files a stranger can list",[140,217,218],{},[17,219,186],{},[140,221,222],{},"The public flag on each storage bucket, which is separate from your table rules",[122,224,225,228,232],{},[140,226,227],{},"Who can sign in to your Supabase account",[140,229,230],{},[17,231,186],{},[140,233,234],{},"A password nobody else has, and two-factor on the account",[10,236,237],{},"Every row in the bottom half is a setting, and every setting is a few minutes in\na dashboard. The platform arrives production-grade. The configuration arrives in\nwhatever state your builder left it in.",[22,239,241],{"id":240},"how-do-i-check-my-own-project","How do I check my own project?",[10,243,244],{},"Three places, and none of them needs you to read a line of SQL.",[10,246,247,250],{},[17,248,249],{},"Open the Security Advisor in your Supabase dashboard."," It lists every table\nwith Row Level Security switched off, which is the bluntest version of this\nproblem, and Supabase is good at flagging it. A project with an empty list there\nhas cleared the first question.",[10,252,253,256,257,261],{},[17,254,255],{},"Then read the policy on any table holding people."," The Advisor cannot decide\nwhether a permissive policy was deliberate, because on a product catalogue it\nwould be correct. A table can have the switch on, a valid policy, a green tick in\nthe dashboard, and still hand its rows to anyone who asks;\n",[33,258,260],{"href":259},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","the four states a table can be in","\nwalks through how to tell yours apart.",[10,263,264,267,268,39],{},[17,265,266],{},"Then look at Storage."," Buckets have their own settings and your table rules do\nnot reach them, so a locked-down database tells you nothing about\n",[33,269,271],{"href":270},"\u002Fblog\u002Fsupabase-storage-bucket-public","the files your users uploaded",[72,273],{"alt":274,"caption":275,"src":276},"A thick outer wall carrying a ticked SOC 2 plaque runs across the back. In front of it stands a smaller enclosure with three doors, each labelled in mono: RLS, public, and service_role.","The wall behind is inspected by somebody else. These three handles are inside your own project, and each one is a page in your dashboard.","\u002Fblog\u002Fis-supabase-secure\u002Fthree-doors-you-own-1600x700.png",[10,278,279,280,284,285,39],{},"There is a fourth question the dashboard cannot answer: which key your app\nactually shipped. The settings page lists the keys your project holds, and your\napp is the only place that records which one went into it. Reading the key in\nyour own live page is\n",[33,281,283],{"href":282},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","a two-minute job",", or our free\nscan reads it for you along with everything above: ",[33,286,107],{"href":106},[22,288,290],{"id":289},"what-to-do-now","What to do now",[292,293,294],"key-takeaways",{},[295,296,297,301,304,307,310],"ul",{},[298,299,300],"li",{},"Stop asking whether Supabase is secure. It is, with a SOC 2 Type 2 report, ISO 27001, AES-256 encryption at rest and regular penetration tests behind the claim.",[298,302,303],{},"Read the boundary in their own words. The compliance covers the Supabase product, and your Row Level Security policies, keys and buckets sit on your side of it.",[298,305,306],{},"Open the Security Advisor first. It costs a minute and it answers the bluntest version of the question.",[298,308,309],{},"Read the policy on every table holding people, because a permissive policy shows in the dashboard as a protected table.",[298,311,312],{},"Check Storage separately from your tables. The two have different settings and a strict database says nothing about your files.",[10,314,315,316,320,321,39],{},"If you would rather work through the whole thing as a list, the\n",[33,317,319],{"href":318},"\u002Fchecklist","10-minute security checklist"," covers this alongside the other\nsettings worth closing in a newly launched app, and there is a plain language\nwalkthrough of the specifics for ",[33,322,324],{"href":323},"\u002Fis-your-supabase-app-safe","Supabase apps",[10,326,327,328,39],{},"Working through that list is an evening, and the answer it gives you is true on\nthe evening you do it. Keeping it true is the part that does not fit in one,\nwhich is what we built Reeve Care for: it re-runs these same checks on your app\non a schedule and emails you when one of them starts answering differently.\n",[33,329,331],{"href":330},"\u002F#pricing","What it watches and what it costs",[22,333,335],{"id":334},"reeve-keeps-a-copy-of-your-supabase-database","Reeve keeps a copy of your Supabase database",[10,337,338],{},"Outside the account it came from, on a schedule, and verified before it counts.\nThe first of those three is the one Supabase's own backups cannot do for you.",[10,340,341],{},"Supabase takes a daily copy on a paid plan and none at all on the free one, and\neither way that copy sits inside the project it was taken from. It is the right\ntool for the afternoon you break your own data. It is out of reach on the day\nthe account itself is the problem: a billing lapse, a deletion, a login nobody\ncan get into.",[10,343,344],{},"Reeve Care keeps a copy somewhere else. Taken on the schedule your plan sets,\nencrypted before it leaves the machine that made it, and read back and checked\nbefore we count it as a backup at all, so the date on your dashboard is the date\na copy was proven to exist rather than the date a job started. It covers your\nSupabase database, and the files your users uploaded once you connect them.",[10,346,347],{},"A restore does three things around the replay itself. It checks the copy still\nfits your database before it puts back a single row, it takes a safety snapshot\nof what is there now first, and it proves the database is writable afterwards by\nwriting to it, because a restore that leaves you read-only has not finished. You\ncan also download any copy we hold and walk away with it.",[10,349,350,351,39],{},"Every check on this page tells you where your app stands today. The backups are\nfor the day something has already gone wrong.\n",[33,352,354],{"href":353},"\u002Fsupabase-backups","What Reeve backs up on Supabase, how often, and what a restore does",{"title":356,"searchDepth":357,"depth":357,"links":358},"",3,[359,361,362,363,364,365,366],{"id":24,"depth":360,"text":25},2,{"id":48,"depth":360,"text":49},{"id":82,"depth":360,"text":83},{"id":110,"depth":360,"text":111},{"id":240,"depth":360,"text":241},{"id":289,"depth":360,"text":290},{"id":334,"depth":360,"text":335},"Security basics","\u002Fblog\u002Fis-supabase-secure\u002Fcover-1200x630.png","A building of lit windows with one pane on an upper floor swung open, leaving a dark gap in an otherwise sealed facade.","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.",false,"md",[374,377,380,383,385,388],{"q":375,"a":376},"Is Supabase secure enough to hold real customer data?","Yes. Supabase is SOC 2 Type 2 compliant and ISO 27001 certified, encrypts customer data at rest with AES-256 and in transit with TLS, and runs regular penetration tests. What that does not tell you is whether the rules inside your own project let a stranger read your tables, because that setting belongs to your project rather than to the platform.",{"q":378,"a":379},"Is Supabase SOC 2 compliant?","Yes, SOC 2 Type 2. Enterprise and Team customers can request the report from their dashboard. The scope is the Supabase product itself: their infrastructure, their controls, their monitoring.",{"q":381,"a":382},"Does Supabase's SOC 2 report cover my app?","No, and Supabase says so in writing. Their SOC 2 documentation states that the compliance does not transfer to environments outside of the Supabase product or Supabase's control, and that data on the customer side of that boundary is the responsibility of the customer. Your Row Level Security policies, your API keys and your storage settings are all on your side of it.",{"q":111,"a":384},"Yes, and the work that makes it safe on your side is short. Turn on Row Level Security for every table holding real data and write a policy that names a condition, keep the secret key out of anything your visitors download, and check which storage buckets are marked public. Those three are the settings that decide whether a stranger can reach your data, and they are where we start when we scan an app.",{"q":386,"a":387},"Is Supabase HIPAA compliant?","Supabase offers HIPAA compliance, and it is not automatic. It requires the HIPAA add-on and a signed Business Associate Agreement, and their documentation is explicit that SOC 2 compliance is no substitute for it. Protected health information also brings rules about where you may put it, including an instruction not to store it in public storage buckets.",{"q":389,"a":390},"Is Supabase more secure than building my own backend?","On the parts Supabase handles, almost certainly. Server patching, database upgrades, encryption at rest, network security and an audited access-control regime are all things a solo founder rarely does as thoroughly. The parts you still own are the same either way, and with your own backend there is one more of them: the code between your app and your database.","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",[393,394,395,396,397,398,399],"is supabase secure","is supabase safe","how safe is supabase","supabase security","is supabase safe for production","supabase shared responsibility model","is supabase soc 2 compliant",{},true,"\u002Fblog\u002Fis-supabase-secure","2026-08-29",{"title":5,"description":370},"blog\u002Fis-supabase-secure",[407,408,409],"Is Supabase secure? The platform is: SOC 2 Type 2, ISO 27001, AES-256 at rest, TLS in transit, and penetration tests they publish.","Supabase's own SOC 2 documentation says that compliance stops at the edge of their product. Your tables, your keys and your storage buckets sit on the other side of that line.","We scanned 30,998 live apps in August 2026. In 2,096 of the 3,680 we could check, a table answered a stranger, on a platform that was working exactly as designed.","5lTATYLlSIh8qrLH7b_JNWdnSOocwDseqCd3agwvgRA",[412,419,425,431,437,443,449,455,461,467,473,479,485,491,497,503,509,515,521,527,533,539,545,551,557,563,564,570,576,582,588,594,599,605,611,616,621,627,633,638,643,649],{"path":413,"title":414,"description":415,"published":416,"category":417,"image":418,"draft":371},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","Backups","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":420,"title":421,"description":422,"published":423,"category":367,"image":424,"draft":371},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":426,"title":427,"description":428,"published":429,"category":367,"image":430,"draft":371},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":432,"title":433,"description":434,"published":435,"category":367,"image":436,"draft":371},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":438,"title":439,"description":440,"published":441,"category":367,"image":442,"draft":371},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":444,"title":445,"description":446,"published":447,"category":367,"image":448,"draft":371},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":450,"title":451,"description":452,"published":453,"category":367,"image":454,"draft":371},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":456,"title":457,"description":458,"published":459,"category":367,"image":460,"draft":371},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":462,"title":463,"description":464,"published":465,"category":367,"image":466,"draft":371},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":468,"title":469,"description":470,"published":471,"category":417,"image":472,"draft":371},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":474,"title":475,"description":476,"published":477,"category":417,"image":478,"draft":371},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":480,"title":481,"description":482,"published":483,"category":417,"image":484,"draft":371},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":486,"title":487,"description":488,"published":489,"category":367,"image":490,"draft":371},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":492,"title":493,"description":494,"published":495,"category":367,"image":496,"draft":371},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":498,"title":499,"description":500,"published":501,"category":367,"image":502,"draft":371},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":504,"title":505,"description":506,"published":507,"category":367,"image":508,"draft":371},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":510,"title":511,"description":512,"published":513,"category":367,"image":514,"draft":371},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":516,"title":517,"description":518,"published":519,"category":367,"image":520,"draft":371},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":522,"title":523,"description":524,"published":525,"category":367,"image":526,"draft":371},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":528,"title":529,"description":530,"published":531,"category":367,"image":532,"draft":371},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":534,"title":535,"description":536,"published":537,"category":367,"image":538,"draft":371},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":540,"title":541,"description":542,"published":543,"category":367,"image":544,"draft":371},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":546,"title":547,"description":548,"published":549,"category":417,"image":550,"draft":371},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":552,"title":553,"description":554,"published":555,"category":367,"image":556,"draft":371},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":558,"title":559,"description":560,"published":561,"category":417,"image":562,"draft":371},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":402,"title":5,"description":370,"published":403,"category":367,"image":391,"draft":371},{"path":565,"title":566,"description":567,"published":568,"category":367,"image":569,"draft":371},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":571,"title":572,"description":573,"published":574,"category":367,"image":575,"draft":371},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":577,"title":578,"description":579,"published":580,"category":367,"image":581,"draft":371},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":583,"title":584,"description":585,"published":586,"category":417,"image":587,"draft":371},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":589,"title":590,"description":591,"published":592,"category":417,"image":593,"draft":371},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":270,"title":595,"description":596,"published":597,"category":367,"image":598,"draft":371},"Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":600,"title":601,"description":602,"published":603,"category":367,"image":604,"draft":371},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":606,"title":607,"description":608,"published":609,"category":417,"image":610,"draft":371},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":98,"title":612,"description":613,"published":614,"category":367,"image":615,"draft":371},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":617,"title":618,"description":619,"published":614,"category":367,"image":620,"draft":371},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":622,"title":623,"description":624,"published":625,"category":367,"image":626,"draft":371},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":628,"title":629,"description":630,"published":631,"category":417,"image":632,"draft":371},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":259,"title":634,"description":635,"published":636,"category":367,"image":637,"draft":371},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":639,"title":640,"description":641,"published":636,"category":417,"image":642,"draft":371},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":644,"title":645,"description":646,"published":647,"category":417,"image":648,"draft":371},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":282,"title":650,"description":651,"published":647,"category":367,"image":652,"draft":371},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1790150951364]