WZ-IT Logo

Supabase for professional secrecy holders

Timo WevelsiepTimo WevelsiepUpdated: 27.08.2026

Editorial note: Versions, commands and prices may change. Please verify critical steps independently before production use. This guide does not replace individual consulting.

Does Supabase need to be operated or migrated for a law firm, medical practice or another organisation handling professional secrets? Assess the Supabase operating model.

Supabase is attractive for AI-generated applications, portals and internal business software because PostgreSQL, authentication, storage, realtime, APIs and functions come together in one platform. That breadth also makes assessment more demanding for professional secrecy holders: a database location alone does not describe where identities, files, logs and server-side functions are processed.

A useful assessment starts with the application and treats Supabase as a complete platform.

Which Supabase components may be involved?

Component Relevance to protected data
PostgreSQL business records, roles, functions, triggers and audit data
Auth identities, providers, sessions, tokens and email flows
Storage documents, images, exports, bucket metadata and share links
Data API direct client access to tables and views
Realtime transmission of changes, broadcast and presence
Edge Functions server-side processing, webhooks and external APIs
Logs errors, metadata, requests and diagnostics
Backups additional copies of database and files

An application may store only case identifiers in PostgreSQL while full documents live in Storage. Conversely, database functions may process sensitive content even when the frontend only displays a shortened version.

Supabase Cloud or self-hosting?

The two models have different responsibility boundaries.

Supabase Cloud

The platform provider operates the environment it supplies. Edition, region, capabilities, support path, service providers and agreements need to be assessed for the intended processing. The Supabase documentation on its security boundary explicitly notes that controls within the Supabase product do not automatically transfer to environments outside that boundary.

Self-hosted Supabase

The open-source stack runs on customer-controlled or managed infrastructure. This creates different choices for location, networking and participating providers. It also gives the operator additional responsibility for:

  • hardening and secrets
  • updates across Supabase components
  • PostgreSQL and platform upgrades
  • monitoring and alerting
  • database and storage backup
  • recovery and scaling
  • SMTP, domains and external services

The official self-hosting documentation explains that self-hosting does not provide the same managed feature set as Supabase Cloud. Required cloud capabilities need to be replaced in the target operating model.

Self-hosting is therefore not an automatic compliance switch. It expands both control and operational responsibility.

RLS and tenant separation

Browser and mobile applications often access the Supabase Data API directly. Row Level Security can constrain access at row level. For client or patient data, review at least:

  • Is RLS enabled on every exposed table?
  • Are there policies for select, insert, update and delete?
  • Are anonymous and authenticated roles separated?
  • Can users modify their tenant or organisation assignment?
  • Are views, functions and RPC calls protected appropriately?
  • Which components use service_role or other privileged roles?
  • Do Storage rules and database permissions align?

Test policies against real user journeys. Reading SQL alone can miss interactions between JWT claims, views and server-side functions.

Authentication is more than a user table

Supabase Auth processes identities, sessions and tokens. The target model should cover:

  • permitted login methods and OAuth providers
  • MFA requirements
  • redirect URLs and domain changes
  • SMTP and auth-email content
  • token and secret lifetime and rotation
  • account suspension, deletion and export
  • administrative user management

During migration, password hashes, provider links or existing sessions may need special handling. The plan should state whether users can be transferred seamlessly or need to sign in again.

Storage, functions and external data paths

Storage buckets and Edge Functions often create the largest blind spots.

For Storage, assess:

  • public and private buckets
  • signed URLs and their lifetime
  • object paths and tenant separation
  • file types, size limits and malware scanning
  • metadata and actual objects in backup

For Functions, assess:

  • secrets and API keys
  • outbound connections
  • webhooks and external recipients
  • request and response logging
  • deployment and versioning
  • error behaviour and retries

A Function can send protected information to an external service even while database and Storage run entirely within a controlled environment.

Backup and recovery

A PostgreSQL dump does not restore all of Supabase. A dependable concept covers:

  1. database schema, roles, data and required extensions
  2. Storage objects and associated metadata
  3. Functions and their deployment state
  4. configuration and secrets under a separate protection model
  5. auth, SMTP, domain and provider configuration
  6. a documented restore into an empty target environment

Retention and deletion need to include additional copies. Back up Supabase completely explains the technical layers in depth.

Migration into a controlled target model

An existing Cloud, Lovable or Firebase backend should not be switched in the first run. Use a controlled path:

  1. Inventory components and dependencies.
  2. Prepare the target environment with networking, auth, backups and monitoring.
  3. Transfer database, Storage, Functions and configuration in a rehearsal.
  4. Test RLS and business user journeys in the target environment.
  5. Define cutover, maintenance window and rollback point.
  6. Perform production cutover and complete documented acceptance.

After migration, the development team can continue working on the application with its familiar AI and development tools. Git pushes are connected to the new Supabase environment through the agreed build and deployment path. Depending on criticality, this includes separate staging and production environments, approvals, database-migration checks and rollback.

The Supabase migration checklist covers the general sequence. WZ-IT offers a technical Supabase migration from EUR 3,490 excluding VAT; the actual scope is assessed before a concrete proposal.

Sources

Rather have it operated?

You'd rather not run Section 203 & Managed Cloud yourself? WZ-IT handles setup, operations and maintenance - privacy-focused from Germany.

Enquiry

Assess the application and operating model

Describe the application, data types, and current situation. We will assess which technical starting point fits the intended operations without obligation.

How should we get back to you?

Frequently Asked Questions

Answers to the most important questions

No. Suitability depends on the operating model, application, data flows, service-provider chain, agreements, permissions and technical measures.

Not as a blanket rule. Cloud and self-hosting have different responsibility boundaries. The concrete setup must meet the professional, legal and operational requirements.

RLS is important, but needs to be enabled and tested completely. Service roles, functions, storage, server-side APIs and metadata require additional review.

Alongside PostgreSQL, include storage objects and metadata, configuration, functions, secrets and a documented recovery path.

Yes. Database, auth, storage, functions, RLS, integrations and cloud-specific capabilities are reviewed in a test migration before cutover.

Contact

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Email
[email protected]
Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.