apps/docs/content/guides/security/security-testing.mdx
Supabase customer support policy for penetration testing
Customers of Supabase are permitted to carry out security assessments or penetration tests of their hosted Supabase project components. This testing may be carried out without prior approval for the customer services listed under permitted services. Supabase does not permit hosting security tooling that may be perceived as malicious or part of a campaign against Supabase customers or external services. This section is covered by the Supabase Acceptable Use Policy (AUP).
It is the customer’s responsibility to ensure that testing activities are aligned with this policy. Any testing performed outside of the policy will be seen as testing directly against Supabase and may be flagged as abuse behaviour. If Supabase receives an abuse report for activities related to your security testing, we will forward these to you. If you discover a security issue within any of the Supabase products, contact Supabase Security immediately.
Furthermore, Supabase runs a Vulnerability Disclosure Program (VDP) with HackerOne, and external security researchers may report any bugs found within the scope of the aforementioned program. Customer penetration testing does not form part of this VDP.
https://<customer_project_ref>.supabase.co/*https://db.<customer_project_ref>.supabase.co/*The customer agrees to the following,
Security testing: