Security & data protection
Status: ⚠️ Compliance
Scope
Supabase RLS is already household-scoped. This feature covers the remaining posture: encryption at rest and in transit, secret/key rotation cadence, photo storage access controls, and the path to SOC 2 / pen test. Distinct from GDPR (rights) and COPPA (consent) — this is the infrastructure security layer.
Open questions
- Is end-to-end encryption required for photo submissions or is server-side encryption sufficient?
- What is the pen test schedule and who conducts it?
- Is there a SOC 2 Type II roadmap, and at what user/revenue threshold does it become required?
- How are Supabase anon keys rotated and how does the app handle a key rotation event?