In September 2026 the security firm UpGuard scanned about 300,000 domains that showed signs of using Supabase, a hosted database service, and found 16,326 databases whose tables could be read by anyone. More than half showed signs of personal information. Smaller groups held password or login-token fields. [1] The examples UpGuard published included a valet service with more than 100,000 customers' phone numbers and license plates, a Canadian immigration service with 884 plaintext passwords, and a consulate's records on 25,000 people. [1]
The cause was not a break-in. The data was open because the locks were never switched on. UpGuard says the missing piece was row-level security, the setting that decides which rows a given visitor may read. In its account, the setting is on by default when a table is made through Supabase's own dashboard, but not when a table is made through the programming interface, which is the route AI coding tools use. [1] UpGuard also wrote that Supabase "is the database product most recommended by Claude Code." [1] That is a claim by a firm that sells security services, and I could not check it independently.
Supabase's chief information security officer answered that projects are "secure by default" and that security is "a shared responsibility between the company and its customers." [2] Both statements can be true. A product can be safe on the path its makers had in mind and open on the path a new kind of builder takes.
That is the claim of this piece: a default belongs to whoever sets it, and the person who inherits it is the one who pays when it fails. Few of these builders chose to leave their tables open. They never made the choice at all. Someone upstream had made it for them, and the tool that wrote their code did not raise it.
For an investor, this is a diligence question with a short list. Ask what a company's product inherits and who set it: the database defaults, the cloud permissions, the code an AI tool wrote. Ask who reviewed those settings and when. A founder who says "we use a secure platform" has named a vendor, not a control. The harder question is who on the team could say, without looking it up, which tables a stranger can read today.
Sources
- Everything, everywhere: systemic data exposure in Supabase apps, UpGuard, October 1, 2026
- Some Supabase customers are publicly exposing reams of people's data to the web, TechCrunch, September 25, 2026
This piece reports UpGuard's findings and Supabase's response as stated by each. UpGuard's description of the cause, and its statement about which product Claude Code recommends, are the firm's own claims; Supabase disputes that the platform is at fault. The reading that the default's owner is separate from the one who pays is the author's interpretation. This is not investment advice.