Hey everyone,
We just published our 2025 Supabase Security Best Practices Guide, based on findings and common misconfigurations weβve seen during recent pentest engagements.
Itβs a rolling article that we plan to keep updating over time as new issues come up β we still have a few more findings to post about, but wanted to share what weβve got so far.
If youβre running Supabase in production (or planning to), it might help you double-check RLS, Edge Functions, Vault, and other areas where we often see mistakes.
Happy to hear feedback, and weβd love to know if youβve run into similar issues.