Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Does Supabase encrypt data at rest?
- What encryption algorithm is used?
- Which services are covered by the encryption?
- Are there any region - specific considerations?
- How does encryption at rest differ from encryption in transit?
- What should developers know?
- How to verify encryption at rest?
- Conclusion
Key takeaways
- Supabase encrypts every piece of customer data at rest using AES - 256.
- Encryption covers PostgreSQL, Auth, and Storage services in all deployment regions.
- In - transit traffic is protected with TLS, but the focus here is on at - rest protection.
- No additional encryption - at - rest mechanisms are documented beyond AES - 256.
Does Supabase encrypt data at rest?
Yes. Supabase’s official security documentation states that all customer data stored on its hosted platform is encrypted at rest with AES - 256. This applies to the database, authentication service, and file storage.
What encryption algorithm is used?
Supabase uses the AES - 256 cipher for data - at - rest encryption. AES - 256 is a widely - accepted symmetric encryption standard that provides 256 - bit key strength, making it resistant to brute - force attacks with current technology.
Which services are covered by the encryption?
| Service | What is encrypted at rest |
|---|---|
| PostgreSQL database | All tables, indexes, and logs |
| Auth service | User credentials, session tokens, and metadata |
| Storage objects | Files uploaded to Supabase Storage buckets |
Each of these services stores its data on disk within Supabase’s managed infrastructure, and the AES - 256 encryption is applied automatically by the platform.
Are there any region - specific considerations?
Supabase applies the same AES - 256 encryption across all regions where a project is deployed. There is no indication of region - specific variations in the encryption method.
How does encryption at rest differ from encryption in transit?
Encryption at rest protects data stored on physical media from unauthorized access if the storage media is compromised. Encryption in transit, which Supabase also provides via TLS, protects data as it moves between the client and server. Both are complementary: at - rest encryption secures stored data, while TLS secures data while it is being transferred.
What should developers know?
- You do not need to configure encryption yourself; Supabase enables it by default for all projects.
- If you need additional compliance (e.g., customer - managed keys), Supabase currently does not expose a way to supply your own keys; you rely on the platform’s AES - 256 implementation.
- Regularly review Supabase’s security page for updates, as cloud providers may evolve their encryption practices.
How to verify encryption at rest?
Because the encryption is handled by Supabase’s managed infrastructure, there is no direct API to query the encryption status. The assurance comes from the provider’s documented security posture. For audit purposes, you can reference Supabase’s security page and request a SOC 2 or ISO report if needed.
Conclusion
Supabase provides AES - 256 encryption for all data at rest across its core services, ensuring that stored information is protected against physical or logical storage breaches. Coupled with TLS for data in transit, this gives developers a solid baseline for data security on the platform.
Related guides
How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation
Learn how to schedule Decloak scans via the REST API, compare results across runs, and push new or regressed findings to Jira or Linear automatically.
How can Decloak give auditor - ready proof for SOC 2 and ISO 27001 without weeks of manual work?
Decloak’s free and paid scans generate evidence packages and framework mappings that satisfy SOC 2 and ISO 27001 auditors quickly and automatically.
How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?
Use Decloak’s free 15 - second scan to detect hard - coded keys, outdated libraries, missing SRI and mixed content in a single - page app before a formal audit.