Loading…
Supabase is SOC2 compliant
inian,joel
- Source
- Supabase
- Published
- Added to Yomu
Summary
Supabase reports achieving SOC2 Type 1 compliance and later updates the announcement to say it is SOC2 Type 2 compliant. The post explains SOC2’s five Trust Services Criteria and distinguishes Type 1’s point-in-time audit from Type 2’s observation period, while framing customer expectations and data stewardship as the main reasons for pursuing certification. Supabase used Vanta to monitor controls and collect evidence, selected an auditor familiar with SaaS companies and Vanta, and formalized practices covering device security, access control, policies, logging, monitoring, vendor reviews, and repository protection. The process still required substantial manual evidence, and the company found that audit scope and auditor expectations mattered more than achieving a perfect automated-tool score. Supabase also launched a security center and identified HIPAA certification as a next step.
Context
Supabase pursued SOC2 because customers expected the certification, the team was spending substantial time answering security questionnaires, and the company handles sensitive customer data as a database provider. The post also emphasizes that establishing security practices early makes becoming and remaining compliant easier.
Approach / What changed
Supabase evaluated Vanta, Drata, Secureframe, and Tugboat Logic, chose Vanta, and worked with an auditor experienced with SaaS companies. It used Vanta and related systems to address controls and gather evidence, standardized supported operating systems, formalized security policies, configured logging and monitoring, enforced protections such as MFA and encryption, reviewed vendors, and adapted controls to the audit scope.
Takeaways
- SOC2 Type 1 verifies adherence to stated policies at a point in time, while Type 2 evaluates continued compliance during an observation window typically lasting six months to a year.
- Vanta’s automated checks did not eliminate manual evidence collection; Supabase still had to document onboarding and offboarding, security-issue remediation, and other controls with artifacts such as screenshots.
- Supabase found that audit requirements depend on the systems in scope and the auditor, so reaching out to the auditor early was more useful than trying to achieve a perfect Vanta score.