Skip to content

Security Model

This page explains the security assumptions and recommended deployment posture.

Defaults

  • Supabase Studio binds to localhost by default.
  • Secrets and credentials should not be committed to git.
  • Prefer SSH tunneling or a VPN for admin access to internal services.
  • Do not expose admin surfaces to the public internet.

Data and secrets

  • Document where secrets live (env vs database) and how they should be managed.