Supabase logo

Supabase

Open-source Firebase alternative with PostgreSQL database, auth, and storage.

✓ 4 of 32 frameworks
+ 2 partial
Security & General Standards
SOC 2 Type II

Listed on Supabase security page and trust center

SOC 3
?

Not documented on public trust center

SOC 1 Type II
?

Not documented on public trust center

ISO 27001 (Information Security Management)

Listed on Supabase security page and trust center

ISO 27017 (Cloud Security)
?

Not documented on public trust center

ISO 27018 (Cloud Privacy)
?

Not documented on public trust center

ISO 27701 (Privacy Information Management)
?

Not documented on public trust center

ISO 42001 (AI Management Systems)
?

Not documented on public trust center

ISO 9001 (Quality Management)
?

Not documented on public trust center

CSA STAR (Cloud Security Alliance)
?

Not documented on public trust center

HITRUST CSF
?

Not documented on public trust center

BSI C5 (German Cloud Security)
?

Not documented on public trust center

Privacy & Data Transfer
GDPR (EU)

Listed on Supabase security page with DPA available

CCPA / CPRA (California)
~

CCPA language in privacy policy but full compliance not documented

UK GDPR
?

Not explicitly documented

LGPD (Brazil)
?

Not documented on public trust center

PIPEDA (Canada)
?

Not documented on public trust center

DPDP Act (India)
?

Not documented on public trust center

PIPL (China)
?

Not documented on public trust center

EU-US Data Privacy Framework
?

Not documented on public trust center

Swiss-US Data Privacy Framework
?

Not documented on public trust center

Global CBPR (APEC)
?

Not documented on public trust center

Global PRP (APEC)
?

Not documented on public trust center

Industry & Government
HIPAA (US Healthcare)

HIPAA compliant with BAA available for enterprise/team plans

PCI DSS (Payment Card Industry)
~

PCI DSS handled via Stripe (certified Level 1) for payment processing; Supabase itself not directly PCI certified

FedRAMP (US Federal)

Not listed on FedRAMP Marketplace

StateRAMP / TX-RAMP (US State)
?

Not documented on public trust center

DORA (EU Finance)
?

Not documented on public trust center

CJIS (US Law Enforcement)
?

Not documented on public trust center

FINRA (US Broker-Dealers)
?

Not documented on public trust center

IRAP (Australian Government)
?

Not documented on public trust center

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

Not documented on public trust center

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Supabase's posture? Submit a correction.

Submit a correction →

Work at Supabase?

Claim this profile to verify and enrich your compliance data.

Claim this profile →

Compare Supabase with:

← All DevOps & Monitoring tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026