Skip to main content

Security & data protection

Status: ⚠️ Compliance

Scope

Supabase RLS is already household-scoped. This feature covers the remaining posture: encryption at rest and in transit, secret/key rotation cadence, photo storage access controls, and the path to SOC 2 / pen test. Distinct from GDPR (rights) and COPPA (consent) — this is the infrastructure security layer.

Open questions

  • Is end-to-end encryption required for photo submissions or is server-side encryption sufficient?
  • What is the pen test schedule and who conducts it?
  • Is there a SOC 2 Type II roadmap, and at what user/revenue threshold does it become required?
  • How are Supabase anon keys rotated and how does the app handle a key rotation event?