惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
F
Fortinet All Blogs
H
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
MyScale Blog
MyScale Blog
B
Blog
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
博客园_首页
L
LangChain Blog
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky

Supabase Blog

AI Agents Know About Supabase. They Don't Always Use It Right. Custom OIDC Providers for Supabase Auth 100,000 GitHub stars Supabase docs over SSH Navigating Regional Network Blocks Supabase Joins the Stripe Projects Developer Preview Log Drains: Now available on Pro Supabase Storage: major performance, security, and reliability updates Supabase incident on February 12, 2026 Hydra joins Supabase X / Twitter OAuth 2.0 is now available for Supabase Auth BKND joins Supabase Supabase is now an official Claude connector Supabase PrivateLink is now available Introducing: Postgres Best Practices When to use Read Replicas vs. bigger compute Introducing TRAE SOLO integration with Supabase Supabase Security Retro: 2025 Sync Stripe Data to Your Supabase Database in One Click Building ChatGPT Apps with Supabase Edge Functions and mcp-use Own Your Observability: Supabase Metrics API Introducing iceberg-js: A JavaScript Client for Apache Iceberg Introducing Supabase for Platforms Adding Async Streaming to Postgres Foreign Data Wrappers Build "Sign in with Your App" using Supabase Auth Introducing Seven New Email Templates for Supabase Auth The new Supabase power for Kiro Introducing Supabase ETL Introducing Analytics Buckets Introducing Vector Buckets
Supabase is now ISO 27001 certified
Stephen Morgan · 2026-04-22 · via Supabase Blog

Supabase is now ISO 27001 certified

Supabase is now certified to ISO/IEC 27001:2022. The certificate covers our information security management system across the entire platform, including Database, Auth, Storage, Realtime, Edge Functions, and the Data API.

ISO/IEC 27001:2022 is the international standard for information security management systems, also known as an ISMS. An ISMS is the collection of policies, processes, and controls a company uses to manage risk to the information it holds. The standard defines what an ISMS has to cover, how it has to be documented, and how it has to be maintained.

Certification comes from an accredited third-party auditor. They review the documentation, test the controls, and decide whether the standard has been met. A certificate is valid for three years, with a surveillance audit every year in between, and the ISMS has to keep running the whole time. Controls have to keep working. If the system drifts, the certificate goes away.

SOC 2 and ISO 27001 cover a lot of the same ground. Both evaluate how a company protects customer data. Both look at access controls, change management, incident response, and business continuity. A large share of the evidence we already had from SOC 2 mapped cleanly to ISO 27001 controls.

Which one you need depends on where you are:

  • SOC 2 is a report written by your auditor describing how your controls operated over a period of time. It is widely accepted in North America.
  • ISO 27001 is a certificate confirming that your ISMS meets an international standard. It is widely accepted in Europe, Asia, and the public sector.

Some teams need one. Some need both.

Certification happens in two stages. Stage one is a documentation review. The auditor reads your policies, risk assessments, and statement of applicability, then decides whether the ISMS is ready to be tested. Stage two is the audit itself. The auditor interviews staff, samples evidence, and tests whether controls work the way you say they do.

Preparing for an audit is a good procedural exercise:

  • Writing and formalizing policies that had previously existed informally
  • Documenting risk assessments properly
  • Running internal audits
  • Selecting an auditor
  • Mapping SOC 2 controls to the ISO 27001 Annex A list so we were not collecting the same evidence twice

If you are on a Team or Enterprise plan, request the ISO 27001 certificate from your dashboard. That is the document your procurement and security teams will ask for.

If a vendor review required ISO 27001 and blocked you from building on Supabase, you are no longer blocked. If a deal has been waiting on this, talk to your account team.

ISO 27001 is one piece of a broader security and compliance roadmap. We already support SOC2, of course. We already support HIPAA for teams handling protected health information.

If your team has a specific compliance requirement you need from Supabase, tell us. The work we prioritize is shaped by what developers ask us for.