Some Supabase customers are publicly exposing reams of people’s data to the web
UpGuard’s findings show that misconfigurations in Supabase-hosted apps are exposing sensitive data at scale, with roughly 16,000 databases containing publicly accessible personal information such as names, addresses, phone numbers, passwords, and tokens. For CIOs and technology leaders, this is a clear warning that rapid AI-assisted development and “vibe coding” can materially increase breach risk unless IT enforces stronger secure-default controls, configuration governance, and continuous monitoring across managed platforms. The strategic implication is that security can no longer be treated as a developer-only concern; IT organizations need standardized guardrails, automated exposure detection, and shared accountability with cloud/application teams.
