Enterprise-grade security protecting your financial data
We understand that you're entrusting us with your most sensitive business data. Security isn't an afterthought—it's built into every layer of our infrastructure. Here's exactly how we protect your information.
Your data, your control
Supabase infrastructure
Data encrypted at rest
Continuous security improvements
How we protect your most sensitive data
All API keys are encrypted at rest using military-grade AES-256 encryption. Even our own engineers cannot view your credentials in plain text.
Encryption keys are stored in a separate Hardware Security Module (HSM) with strict access controls and regular rotation.
We only request read-only API scopes. We cannot and will not modify, delete, or write any data to your connected services.
Disconnect any integration instantly. We immediately delete all associated credentials from our systems.
Multiple layers of protection
All data in transit is encrypted using the latest TLS 1.3 protocol with perfect forward secrecy.
Enterprise-grade DDoS mitigation protects against attacks up to 100 Gbps.
Advanced WAF blocks SQL injection, XSS, and other OWASP Top 10 vulnerabilities.
Real-time monitoring and automated threat detection across all systems.
Quarterly security audits by independent third-party firms to identify vulnerabilities.
Databases run in isolated environments with no public internet access.
Who can access your data and how we track it
Strict least-privilege access controls. Engineers can only access production data with approval and logging.
Every access to sensitive data is logged with who, what, when, and why. Logs are immutable and retained for 7 years.
All employees with data access undergo comprehensive background checks and security training.
Ensuring your data is always safe and recoverable
Full database backups every 6 hours, retained for 30 days. Point-in-time recovery available within 5 minutes.
Data replicated across multiple availability zones and regions for 99.99% durability and disaster recovery.
In the unlikely event of a security incident, we have a documented response plan:
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:
Security Email
security@obsidian.comResponse Time
Within 24 hours
We offer a bug bounty program for responsible disclosure. Visit our security page for details.