It watches, continuously
Your Supabase auth, API, database, Storage and Edge Function logs, read around the clock — not scanned once and forgotten.
Defencecore watches your Supabase app, explains threats in plain language, and gives your coding agent a safe fix plan.
2-minute setup
Read-only by default
Row level security was turned off on public.invoices from the Supabase SQL editor. Every row in that table is now reachable through the auto-generated API by anyone holding the anon key.
postgres.log statement="ALTER TABLE public.invoices DISABLE ROW LEVEL SECURITY;" -- user: [email protected] -- source: dashboardpostgres.log user_name=postgres database_name=postgres application_name=SupabaseEndpoint detection watches a laptop, explains what it found in a sentence, and hands you the next step. Think of Defencecore as EDR-like protection for AI-built backends — the same job, done for your Supabase project instead of a machine.
Connect your Supabase project read-only in about two minutes. Defencecore watches the logs it already writes — auth, Postgres, API, Storage, Edge Functions — and opens an incident in plain English the moment something is wrong, with the log lines that prove it.
See how it works ↓Defencecore turns noisy platform logs into clear answers your whole team — and your coding agent — can act on.
Your Supabase auth, API, database, Storage and Edge Function logs, read around the clock — not scanned once and forgotten.
Every incident says what happened and which project it hit, in a sentence — no SQLSTATE codes and no log-query language to learn.
Every incident carries the correlated entities and the raw log lines the rule matched, so you can confirm or dismiss it in seconds.
An ordered fix plan you can act on or paste to Claude Code or Cursor. Defencecore is read-only by design — it plans the fix and never touches production itself.
Email and password, or a magic link. No card required for the trial.
Choose your production project and authorize read-only log access.
Incidents open as rules match, each with its evidence and a first action to take.
✓ Account created
✓ Supabase authorized — read-only
✓ defencecore-prod on the watchlist
✓ First logs normalized
Everything you need to watch one production Supabase project, without enterprise contracts or per-seat pricing.
Defencecore watches Supabase platform logs across authentication, API traffic, Postgres, Storage, Realtime, and Edge Functions, and runs detection rules over all of them together.
No — EDR is the closest analogy, not the category. Endpoint detection watches processes on a machine; Defencecore watches the logs your Supabase project already writes across auth, Postgres, the API, Storage and Edge Functions. The comparison is useful because the job has the same shape: watch continuously, explain the finding in a sentence, and hand over the next step. The surface being watched is a production backend rather than a laptop.
No. It is read-only. It detects, explains, and recommends what to investigate, and holds no path that could alter your project — the monitor can never become the incident.
Defencecore is $29 per month with a 7-day trial, covering one monitored Supabase project. That is on top of whatever you pay Supabase; Defencecore does not change your Supabase bill.
Yes. Defencecore reads logs through the Supabase Management API, which works regardless of your plan. It matters more on the free plan, in fact, since free-tier log retention is short and Defencecore keeps the flagged events and incidents after the originals expire.
Not today, and we would rather say so plainly than imply otherwise. Defencecore stores security log metadata and the log lines attached to incidents, so if your Supabase logs contain PHI, that data would reach Defencecore. There is no BAA available yet. If you are handling PHI, talk to us before connecting a project.
Log ingestion starts on the next worker run, within minutes of authorizing Supabase. Whether you see an incident depends on whether anything in your logs matches a rule — a quiet first day means your project is quiet, and the Activity view shows the logs arriving either way.
No. Defencecore translates security events into plain language and shows the evidence behind every finding, so you can act on it without knowing what SQLSTATE 42501 means.
Connect your Supabase project and put a security operator on the backend your AI built.
Start for $29 ↗