Security is at the core of everything we build at SoupCMS. We understand that you're trusting us with access to your Supabase database, and we take that responsibility seriously.
Our Security Principles
Encrypted Connections
All connections use TLS 1.3 encryption. Your credentials and data are never transmitted in plain text.
Row Level Security
SoupCMS fully respects Supabase's Row Level Security policies. Your existing security rules are always enforced.
SOC 2 Compliant Infrastructure
Our infrastructure is hosted on SOC 2 compliant cloud providers with enterprise-grade security controls.
Credential Security
Your Supabase credentials are encrypted at rest and never logged. You can revoke access at any time.
Regular Security Audits
We conduct regular security assessments and penetration testing to identify and address vulnerabilities.
Data Architecture
SoupCMS uses a security-first architecture that prioritizes your data protection:
- Encrypted Storage: Any sensitive data we store, such as your Supabase connection credentials, is encrypted at rest using industry-standard encryption.
- Minimal Data Collection: We only store the minimum information needed to provide the service: your account details, project configurations, and view preferences.
- Secure Key Management: API keys and credentials are stored securely and are never exposed in logs or client-side code.
Authentication & Access Control
We implement multiple layers of authentication and access control:
- Secure authentication via email/password or OAuth providers
- Session tokens with automatic expiration
- Optional two-factor authentication (2FA)
- Team-based access controls with role permissions
- Audit logs for all administrative actions
Infrastructure Security
Our infrastructure is built with security-first principles:
- Hosted on enterprise-grade cloud infrastructure
- DDoS protection and Web Application Firewall (WAF)
- Automated security patching and updates
- Network isolation and segmentation
- 24/7 monitoring and alerting
Compliance
We are committed to meeting industry standards and regulatory requirements:
- GDPR compliant data handling practices
- SOC 2 Type II certification (in progress)
- Regular third-party security audits
- Data Processing Agreements (DPA) available for enterprise customers
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to us at [email protected]. We commit to:
- Acknowledging your report within 24 hours
- Providing regular updates on our investigation
- Working with you to understand and resolve the issue
- Recognizing your contribution (if desired)
Questions?
If you have questions about our security practices or need additional information for your compliance requirements, please contact us. We're happy to provide additional documentation or discuss specific security concerns.