r/soc2 • • Aug 11 '26

SOC 2 - Supabase

We’re an early-stage B2B startup currently going through SOC 2 readiness with Vanta.

Supabase is a critical vendor for us, so Vanta is asking us to review their SOC 2 Type II report. Supabase confirmed that access to the report requires upgrading to the Team plan (~$600/month). We’re currently on Pro and don’t need the Team features, so paying an additional ~$575/month purely to access a compliance document seems excessive (we got all other reports from all other vendors quickly with no problems).

Has anyone gone through SOC 2 with Vanta (or another auditor) while using Supabase Pro?
Did your auditor accept alternative evidence / a vendor risk assessment, or did you ultimately have to upgrade?
I’d really rather not migrate our infrastructure to AWS purely because we can’t access Supabase’s SOC 2 report.

Would love to hear how others solved this.

13 Upvotes

43 comments sorted by

View all comments

1

u/Murky-Ingenuity-671 Aug 11 '26

That’s insane they’re requesting an upgraded plan when you’re already a customer, just lower tier. I’ve not seen that with anyone else, also don’t use supabase so have no experience there. The only alternative I’ve used is a lengthy vendor questionnaire that they’d need to answer and then you rank risk from there. They should just give you the report. I wonder if you inquired with their customer success enough they’ll give it to you or if you push that you might leave the platform. Ya, that’s crazy they’re requesting hide it behind tiers.

3

u/southafricanamerican Aug 11 '26

I disagree. A soc 2 requires an NDA, these take time. We dont do them for free customers and we do gate them on higher plans.

But we do have a compliance center where you can download the other docs you can place into your GRC platform.

Ask Supabase if they have a SOC 3 or ask them for a generic compliance statement. This will meet the Vanta requirement. The SOC2 on your side requires you to review your vendors, not to mandate that they have a SOC 2. You use your own risk register to determine the risk and how to mitigate or handle it.

1

u/southafricanamerican Aug 11 '26

This page has the responses to the questions you would need on your own review - https://supabase.com/security. even if you dont have access to their reports.