Back to Guides
Guide2 October 2026

Does Supabase encrypt data at rest and how does it work?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Does Supabase encrypt data at rest?
  3. What encryption algorithm is used?
  4. Which services are covered by the encryption?
  5. Are there any region - specific considerations?
  6. How does encryption at rest differ from encryption in transit?
  7. What should developers know?
  8. How to verify encryption at rest?
  9. Conclusion

Key takeaways

Does Supabase encrypt data at rest?

Yes. Supabase’s official security documentation states that all customer data stored on its hosted platform is encrypted at rest with AES - 256. This applies to the database, authentication service, and file storage.

What encryption algorithm is used?

Supabase uses the AES - 256 cipher for data - at - rest encryption. AES - 256 is a widely - accepted symmetric encryption standard that provides 256 - bit key strength, making it resistant to brute - force attacks with current technology.

Which services are covered by the encryption?

ServiceWhat is encrypted at rest
PostgreSQL databaseAll tables, indexes, and logs
Auth serviceUser credentials, session tokens, and metadata
Storage objectsFiles uploaded to Supabase Storage buckets

Each of these services stores its data on disk within Supabase’s managed infrastructure, and the AES - 256 encryption is applied automatically by the platform.

Are there any region - specific considerations?

Supabase applies the same AES - 256 encryption across all regions where a project is deployed. There is no indication of region - specific variations in the encryption method.

How does encryption at rest differ from encryption in transit?

Encryption at rest protects data stored on physical media from unauthorized access if the storage media is compromised. Encryption in transit, which Supabase also provides via TLS, protects data as it moves between the client and server. Both are complementary: at - rest encryption secures stored data, while TLS secures data while it is being transferred.

What should developers know?

How to verify encryption at rest?

Because the encryption is handled by Supabase’s managed infrastructure, there is no direct API to query the encryption status. The assurance comes from the provider’s documented security posture. For audit purposes, you can reference Supabase’s security page and request a SOC 2 or ISO report if needed.

Conclusion

Supabase provides AES - 256 encryption for all data at rest across its core services, ensuring that stored information is protected against physical or logical storage breaches. Coupled with TLS for data in transit, this gives developers a solid baseline for data security on the platform.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary