Security is the table we set every plate on.
The architecture, the controls, the incident-response playbook — written for security reviewers, not buried in marketing prose.
Architecture
Six pillars, one platform.
The controls we treat as table stakes, not as differentiators.
Tenant isolation
Every business row carries an organization_id and is scoped by Postgres row-level security. A normal Supabase client cannot read across tenants; an admin client bypasses RLS only on server-only trusted paths.
Encryption at rest and in transit
All data is encrypted at rest in managed Postgres and managed object storage. Transport is TLS 1.2+ with modern cipher suites. Backups are encrypted with provider-managed keys.
Strict authentication
Supabase Auth handles identity, with mandatory MFA for org admins. Session cookies are HttpOnly, Secure, SameSite=Lax, scoped to the workspace host. We rotate signing keys and detect anomalous sessions.
Immutable audit log
Every privileged action — publish, review decision, certificate issuance, settings change — is logged with actor, timestamp, and payload diff. Logs are append-only and retained per plan.
Least-privilege access
Our team uses scoped, short-lived credentials. Production access requires hardware-backed MFA and is granted through a just-in-time approval flow. No standing access to customer data.
Network controls
Production runs in isolated VPCs with private subnets for data tiers. Outbound network access is allowlisted. Edge traffic terminates TLS at a managed load balancer with WAF rules.
Compliance
The frameworks we work with.
Where we have certifications, you'll see the artefact. Where we're on the roadmap, you'll see the timeline.
EU data protection regulation. DPA available on request.
UK extension of the GDPR with equivalent protections.
In progress — audit window opens Q3 2026.
Roadmap target for 2027.
Standard Contractual Clauses for international transfers.
California Consumer Privacy Act — supported via in-product tools.
Incident response
What happens when something goes wrong.
A rehearsed playbook, not a wiki page that was last updated in 2024.
Detect
Internal monitoring, customer reports, and an annual third-party penetration test.
Triage
Severity rated within one hour of detection. High-severity incidents escalate immediately.
Contain
Affected systems isolated, credentials rotated, evidence preserved for post-mortem.
Notify
Customers notified within 72 hours where personal data is affected, per GDPR.
Resolve
Root cause identified, fix deployed, monitoring heightened for related signals.
Post-mortem
Public summary shared within 14 days, with the timeline, root cause, and remediations.
Data residency
Where your data lives.
You choose the region at workspace creation. Migration is available on the Enterprise tier.
EU (default)
Frankfurt region. Suitable for EU-resident participants and most EU/EEA customers.
US
AWS us-east-1. Suitable for US-resident participants and US-regulated workloads.
Custom
Enterprise customers can request a specific Supabase region. Discuss with sales.
Sub-processors
Who handles data on our behalf.
Each is governed by a written data processing agreement.
Report a vulnerability
We pay attention to responsible disclosure.
If you find a security issue, please tell us — we acknowledge within one business day and credit researchers in our public hall of fame.
How to report
- Email security@setec-millenium.app with a reproduction and an impact assessment.
- Avoid testing on production data — we have a sandbox you can request.
- We will not pursue legal action against good-faith research that follows this policy.
- We acknowledge within one business day, triage within 72 hours, and publish a public timeline once resolved.
Out of scope
Denial-of-service attacks, social engineering of our staff, physical intrusion, and issues in third-party providers we do not control are out of scope. Spam or phishing through the Service should be reported to support instead.
Security questionnaire?
Send us your CAIQ, SIG, or your own spreadsheet.
Standard questionnaires get a 5-business-day turnaround. Custom ones get a human to read them, and a human to answer.