Monitor Supabase compliance pages

Open-source Firebase alternative โ€” Postgres database, authentication, storage, realtime, edge functions, and pgvector for AI applications.

Supabase publishes several compliance and legal pages that change over time. Under GDPR Article 28, data controllers using Supabase as a processor must continuously verify that "sufficient guarantees" remain in place โ€” which means tracking changes to these pages as they happen. Below are the 4 most relevant pages, what typically changes on each, and ready-to-paste monitoring prompts.

Monitor all 4 pages automatically

Choose the pages that matter most and get an alert when something meaningful changes. The free plan covers 3 monitors.

Start with 3 free monitors โ†’

Pages to monitor

Sub-processor list

https://trust.supabase.com/ โ†—

Typical change frequency: quarterly

What to monitor

  • AWS regional sub-processors (project location is customer-selectable)
  • Fly.io or other edge infrastructure partners
  • Auth MFA delivery sub-processors
  • Support tooling third parties

Suggested monitoring prompt

Alert me when Supabase updates sub-processors, especially cloud regions and MFA delivery partners. Report name and purpose.

Data Processing Agreement

https://supabase.com/legal/dpa โ†—

Typical change frequency: yearly

What to monitor

  • Changes to project-region data residency
  • Updates to pgvector and AI feature provisions
  • Modifications to log retention for Studio access
  • Transfer mechanism changes

Suggested monitoring prompt

Monitor the Supabase DPA for changes to project residency, AI feature provisions, log retention, or transfer mechanisms.

Privacy policy

https://supabase.com/privacy โ†—

Typical change frequency: yearly

What to monitor

  • Changes to Studio telemetry collection
  • Updates to Supabase AI Assistant data usage
  • New data sharing with integration partners
  • Changes to billing and usage data retention

Suggested monitoring prompt

Alert me when Supabase changes Studio telemetry, AI Assistant data, or integration partner sharing. Ignore editorial changes.

Status page

https://status.supabase.com/ โ†—

Typical change frequency: weekly

What to monitor

  • Per-region database incidents
  • Auth service availability
  • Realtime and Edge Functions issues
  • Studio (dashboard) availability

Suggested monitoring prompt

Alert me on Supabase incidents affecting database, auth, realtime, edge functions, or studio โ€” specify region. Ignore minor issues.

Compliance certifications

SOC 2 Type IIHIPAA (Team/Enterprise)GDPR

Data location

Hosting locations: Multiple AWS regions globally (customer-selectable per project)

EU-US Data Privacy Framework: Certified

Related

Ready to start monitoring Supabase?

Set up monitoring free โ†’