Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- How much does each Supabase tier cost?
- What resources are included in the Free plan?
- When does the Pro plan become more cost - effective?
- How does the Team tier improve security and compliance?
- What extra security features are available on Enterprise?
- How are compute resources priced?
- Example: Cost of a Pro organization with two Micro instances
- What add - ons can increase the bill?
- How does billing work across organizations and projects?
- Which plan should you pick for your security posture?
- Bottom line
Key takeaways
- Free gives you a functional dev environment but no compliance guarantees.
- Pro adds paid compute credits, higher usage limits, and email support for $25/month per organization.
- Team ($599/month) includes SOC 2, ISO 27001, SSO, and longer log retention.
- Enterprise is custom - priced and provides full compliance suites, private networking, and 24/7 premium support.
- Compute instances are billed hourly; a typical two - project Pro setup costs about $35/month.
How much does each Supabase tier cost?
Supabase charges a flat monthly fee per organization for the base tier, then adds hourly compute costs per project. The Free tier is $0/month, Pro is $25/month, Team is $599/month, and Enterprise pricing is negotiated per customer.
What resources are included in the Free plan?
The Free plan provides unlimited API requests, 50 k monthly active users (MAU), 500 MB shared - CPU database storage, 5 GB egress plus 5 GB cached egress, 1 GB file storage, and up to two active projects. It includes community - only support and no formal compliance certifications.
When does the Pro plan become more cost - effective?
Pro adds 100 k MAU (extra MAU $0.00325), 8 GB DB per project ($0.125/GB beyond), 250 GB egress ($0.09/GB beyond), 250 GB cached egress ($0.03/GB beyond), 100 GB file storage ($0.0213/GB beyond), email support, 7 - day log retention, daily backups, and a $10/month compute credit that covers one Micro instance. If you need a Micro compute instance ($10/month) for a single project, the $10 credit offsets the cost, making the net extra charge $0 for that instance.
How does the Team tier improve security and compliance?
Team ( $599/month) includes everything in Pro plus:
- SOC 2 and ISO 27001 compliance certifications.
- Project - scoped and read - only access controls.
- Single Sign - On (SSO) for the Supabase dashboard.
- Priority email support with service - level agreements (SLAs).
- Daily backups for 14 days and log retention for 28 days. These features satisfy many regulated - industry requirements and reduce the risk of data leakage.
What extra security features are available on Enterprise?
Enterprise adds a custom - priced package that builds on Team and adds:
- Dedicated support manager and 24 × 7 × 365 premium support.
- Uptime SLAs and AWS PrivateLink for private networking.
- Private Slack channel for direct engineering assistance.
- Custom security questionnaires and audit assistance.
- Optional HIPAA add - on and any additional compliance certifications the customer requires. These controls are designed for large organizations that need guaranteed availability and rigorous audit trails.
How are compute resources priced?
Supabase bills compute per project, hourly, based on instance size. The smallest Micro instance costs $10 per month (assuming full - month usage) and provides 2 - core ARM CPU, 1 GB RAM, and 60 direct connections. Larger instances scale up to XL ( $210/month) and beyond. Pricing is hourly, so you only pay for the minutes the instance runs.
Example: Cost of a Pro organization with two Micro instances
Base plan fee: $25
Compute credit (included): -$10
Project 1 Micro compute: $10
Project 2 Micro compute: $10
Total monthly cost: $35
The example shows that the $10 compute credit covers one Micro instance; the second instance adds $10 to the bill.
What add - ons can increase the bill?
Supabase offers optional add - ons billed per project or per month:
- Point - in - Time Recovery: $100/month for 7 - day retention.
- Custom Domain: $10 per domain.
- Database Branching: $0.01344 per branch - hour.
- Advanced MFA (Phone): $75/month for the first project, $10 for each additional.
- SAML/SSO Auth: 50 MAU free, then $0.015 per extra MAU.
- Log Drains: $60 per drain + usage fees.
- Image Transformations: first 100 origin images free, then $5 per 1 000 images. These can quickly add up, so monitor usage in the Supabase dashboard.
How does billing work across organizations and projects?
Supabase uses organization - based billing: you select a tier for the organization, and each project runs its own compute instance that is billed separately. Spend caps are enabled by default on Pro and higher tiers, automatically stopping extra usage unless you disable them. Taxes (sales tax, VAT, GST) are applied based on the billing address.
Which plan should you pick for your security posture?
- Free is fine for hobby projects or early prototypes where compliance is not required.
- Pro works for production apps that need email support, backups, and a modest compute budget but do not need formal certifications.
- Team is the sweet spot for regulated businesses that must demonstrate SOC 2 or ISO 27001 compliance and need stronger access controls.
- Enterprise is for large - scale, mission - critical deployments that demand custom SLAs, private networking, and full audit support.
Bottom line
Supabase’s tiered pricing lets you start for free and scale up with predictable compute costs. Security - focused teams should consider the Team or Enterprise plans to obtain compliance certifications and advanced access controls, while smaller teams can rely on Pro’s spend caps and backup features to keep costs low.
All numbers are taken from Supabase’s public pricing page as of September 2024.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.