ISO 27001 Compliance #17659
Update: Supabase will work with Enterprise customers to assess any specific ISO27001 controls that are not covered in the SOC2 reportSupabase has done an incredible job achieving both SOC2 Type II and HIPAA Compliance but I could not find anything speaking to plans for ISO 27001 compliance. Would love to know the timeline/roadmap for this level of compliance which many financial institutions ask for. Thanks. |
Replies: 10 comments 7 replies
|
Supabase mentioned earlier in 2022 that they were also aiming for ISO 27001. However, it seems that they have removed all references to it and do not mention ISO 27001 anymore. A brief statement would be appreciated regarding whether they still intend to pursue this certification or not. |
|
I'm Haydn from the Growth team at Supabase. Currently, Supabase is SOC2 Type 2 compliant but not ISO27001 compliant. We've noticed a significant overlap between both standards. While Supabase isn't ISO27001 compliant, we can collaborate with customers under an Enterprise Plan to assess any specific ISO27001 controls your team identifies that are not covered in Supabase's SOC2 report. We can then work towards implementing the necessary controls to meet ISO standards within an agreed timeframe. If you would like to explore this option please submit a support ticket, myself or someone on the team would be happy to chat. |
|
Just chiming in to bump and check if there has been any update on this - would be great to have ISO 27001 in addition to SOC 2 type 2 certification, comparable service providers such as Vercel have both. |
|
Bump from me as well. Especially because many things are changing in America now, an ISO 27001 certification would be significantly more important for some customers. |
|
Bumping this up too |
|
Bump from me as well :) |
|
Interested in this as well! |
|
I'm interested in this as well! |
|
We are currently working on ISO27001 certification for the platform. Our internal audit is complete and we're working toward addressing recommendations from the audit team. I'll come back with more details in the coming weeks. |
|
Bump from me as well :) |
I'm Haydn from the Growth team at Supabase. Currently, Supabase is SOC2 Type 2 compliant but not ISO27001 compliant. We've noticed a significant overlap between both standards. While Supabase isn't ISO27001 compliant, we can collaborate with customers under an Enterprise Plan to assess any specific ISO27001 controls your team identifies that are not covered in Supabase's SOC2 report. We can then work towards implementing the necessary controls to meet ISO standards within an agreed timeframe. If you would like to explore this option please submit a support ticket, myself or someone on the team would be happy to chat.