New security research from cybersecurity company UpGuard says thousands of databases hosted on development platform Supabase are leaving people’s sensitive information exposed to the public web.
TechCrunch spoke with UpGuard, which reported identifying roughly 16,000 databases exposed by Supabase while they were being hosted on the platform. Supabase serves as a hosting service for web and app developers, letting them store and run their databases.
Supabase’s rise and its security track record
This year, Supabase hit a $10 billion valuation because more developers are hosting their vibe-coded apps on the platform. The company has also come under fire over how it handles user security. Plenty of well-documented reports describe users misconfiguring or exposing their databases to the broader internet, in some cases involving millions of records each.
The results show that apps and sites using the vibe-code style can let out sensitive information because the settings are not set up correctly or because there is not enough security put in. Building websites and apps with AI tools is simple, but the code that comes out can sometimes carry security problems, or the apps may need certain settings that the person building them does not know about.
Throughout history, numerous data breaches have been tied to storage servers, databases and websites that were not set up properly. These incidents have led to the leaks of sensitive military emails, immigration and visa applications, classified government files, and hundreds of thousands of driver’s license scans and children’s personal information.
A new surge in data breaches is being fueled by the boom in AI vibe-coding, with many of these breaches now being tied to Supabase as more people store their data there.
What UpGuard found
UpGuard’s research aimed to gauge the scale of exposed data across the platform, and it found publicly accessible names, addresses, phone numbers, and user passwords. A smaller number of passwords and authentication tokens were among the findings.
The firm said the databases held data tied to several projects, including private conversations with sex workers on an Indian adult streaming site, the contact details of people who used an immigration and relocation service, and thousands of license plates of a U.S. valet service. UpGuard said one of the databases belonged to an African government’s consulate in France, and another was used by a virtual SIM farm for intercepting text messages to send one-time passcodes and verify online accounts, typically for launching scams and phishing attacks.
Where the exposed databases live
UpGuard has indicated that this issue is a global one, even though the bulk of the revealed datasets appear to be found in the United States. The new findings continue the earlier research, which found a variety of exposed databases hosted on Supabase, including those belonging to Y Combinator startups and other popular apps.
Supabase’s response
When reached for comment, Supabase’s Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are “secure by default.” He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” he said. “The company notifies affected customers when security issues are discovered.”
The company has not seen the research, but Harmer said its projects are “secure by default.” He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” and the company notifies affected customers when security issues are discovered, he said.
“Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” Harmer added.
The stakes of misconfigured databases
Greg Pollock, an UpGuard security researcher, said the company’s research was important for raising awareness about the issue of data exposures.
Security research shows a familiar dynamic: developers can build apps faster than ever, but the tools they use can carry risk the developer never thinks to check. Supabase offers the platform and the defaults, but the choices about access, encryption and exposure sit with the customer. Harmer described that shared responsibility when he said security is a joint effort.
What developers should check
The findings from UpGuard make clear that relying on defaults alone is not sufficient when you are building on Supabase or any other platform. What is required instead is a working knowledge of how a secure-by-default system operates, so that you can sustain that security rather than trust it by chance.
The records are laid bare for all to see. They are exposed to all who look. What follows is uncertain, and it will be decided by the people who build these systems. The lesson is clear: the default settings are not enough, and the person building the app is always the weakest link.
| Purpose | Exposure Type | Example |
|---|---|---|
| Private conversation archive | Private communications | Sex worker conversations on an Indian adult streaming site |
| Vehicle data | License plates | Thousands of plates for a U.S. valet service |
| Contact information | Names, addresses, phone numbers | Immigration and relocation service users |
| Authentication data | Passwords, tokens | Intercepted text messages from a virtual SIM farm |
| Government data | Classified files | An African government’s consulate in France |
Source material: “Some Supabase customers are publicly exposing reams of people’s data to the web,” TechCrunch.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

