- Sources: primary, discussion
- Summary: TechCrunch reports UpGuard's count of about 16,000 Supabase-hosted databases with publicly reachable names, addresses, phone numbers and user passwords, and a smaller number of passwords and authentication tokens. Supabase's CISO states the company had not seen the research, that projects are secure by default, and that configuration is a shared responsibility. UpGuard's own report was not reached here, the TechCrunch account is the only source read, and no record total is given beyond the database count. No product version is affected, because the exposure is per-project configuration rather than a defect in a released Supabase version.
- Why it matters: The exposure follows from how each project is configured rather than from a platform defect, so the check sits on every team's own access rules rather than on an upgrade.
send feedback on this story