The news
Security firm UpGuard said on September 25, 2026 that it found 16,326 Supabase databases with tables anyone on the internet could read, a Supabase data exposure it tied to missing access rules and misused public keys in apps built on the backend service.
Supabase provides developers with a hosted Postgres database and related services, a category known as backend-as-a-service. In a report written by Greg Pollock, UpGuard's director of research and insights, the firm said it identified about 300,000 unique domains showing signs of Supabase use, using BuiltWith technology fingerprinting and the Chrome UX Report dataset. It then queried each one for a table named “users,” reasoning that it is a common table name.
Of the 16,326 databases with publicly readable tables, more than half had indicators of personally identifiable information, UpGuard said. Fewer held passwords or authentication tokens, according to the report, and only a handful appeared to contain credit card data.
UpGuard described several cases. It said a U.S. valet service exposed records on more than 100,000 customers, including contact details and visit history, plus 665 staff records. A Canadian immigration service exposed about 5,000 records, 884 of them with plaintext passwords. An India-based content platform exposed data on 65,467 users, including personal and financial details and more than 100,000 private messages. An African government consulate exposed physical addresses for 25,000 users, and a Philippines text-message verification service exposed more than 100,000 SMS messages. UpGuard said it notified application owners where it found a significant exposure.
According to UpGuard, the exposures stem from how apps were configured. Row-level security (RLS), the Postgres feature that limits which rows a user can read, was missing or ineffective, and public keys meant to sit in client-side code were treated as if they were secret credentials. UpGuard said that after a developer reported widespread misconfigured Supabase databases built with the Lovable coding platform in March 2025, Supabase changed its Table Editor so tables made there have RLS switched on by default. That safeguard does not cover tables created through the API, the report said, and the API is the route AI coding agents use to work with Supabase.
Supabase's chief information security officer, Bil Harmer, told TechCrunch that projects are secure by default and described security as a shared responsibility between the company and its customers. TechCrunch reported that Supabase reached a $10 billion valuation earlier in 2026.
The numbers
- Databases with publicly readable tables
- 16,326
- Domains checked for Supabase use
- About 300,000
- Exposed databases with signs of personal data
- More than half
- Plaintext passwords at one Canadian immigration service
- 884
- Customers exposed at one U.S. valet service
- More than 100,000
- Supabase valuation (2026, per TechCrunch)
- $10 billion
Why CEOs should care
For CISOs, the risk sits outside the usual review process. Product teams, marketing groups and individual employees can now stand up a working app in days, sometimes with an AI coding agent writing the database code. UpGuard's finding that API-created tables do not get row-level security by default means those projects can go live with customer data readable by anyone who finds the public key in the app's code. Ask for an inventory of every Supabase project tied to company accounts or domains, and require an RLS check on every table before launch.
For buyers and procurement teams, many small software vendors build on services like Supabase. Add a question to vendor security reviews: which backend services hold our data, and how do you verify access controls on every table? A vendor's clean penetration test from last year says little about tables added since.
For general counsel and boards, a publicly readable table holding personal data can raise breach notification questions, depending on the jurisdiction and whether anyone accessed it. Supabase's framing of security as a shared responsibility signals that it expects customers to own their access rules. Boards should ask whether anyone at the company is accountable for apps built outside central IT.
The bigger picture
UpGuard compared the pattern to Amazon's (AMZN) S3 storage service, whose early defaults made it easy to read and write data and, the firm said, led to thousands of data leaks. UpGuard argued that a platform as widely used and as easy to misconfigure as Supabase should rebalance its defaults, as S3 and GitHub have done. AI coding tools speed up the same cycle: they make it easy to create databases and tables quickly, and the security settings depend on how the tool creates them. Until secure defaults cover every path, including the API that agents use, the checks have to happen on the customer side.
What’s next
Watch whether Supabase extends default row-level security to tables created through its API, and whether AI coding tools begin enabling RLS automatically when they build Supabase-backed apps. Companies can act now by scanning their own Supabase projects for tables readable with the public key.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





