Always watching
Continuous Supabase log monitoring catches suspicious auth, API, database, and Edge Function activity.
Defencecore reads your Supabase logs, catches the attacks and misconfigurations hiding in them, and shows you the evidence behind every finding.
2-minute setup
Read-only by default
412 failed sign-ins in 22 minutes from 14 addresses, all against three known account emails. Rate limiting held and no session was issued.
auth.log level=warn msg="invalid_grant" email="[email protected]" ip=83.142.11.204 attempts=57auth.log level=info msg="rate_limit_exceeded" window=60s rejected=188auth.log level=info msg="session_created" count=0 window=30mTraditional security tools assume you have a security team, a SIEM, and someone on call. Defencecore assumes you have a product to ship and nobody watching the logs.
See how it works ↓Defencecore turns noisy platform logs into clear answers your whole team can understand.
Continuous Supabase log monitoring catches suspicious auth, API, database, and Edge Function activity.
Every incident says what happened, which project it hit, and what to do first — no log-query language to learn.
Every incident carries its timeline, the correlated entities, and the raw log lines the rule matched.
Defencecore can read findings and explain risk, but it cannot change your production project.
Email and password, or a magic link. No card required for the trial.
Choose your production project and authorize read-only log access.
Incidents open as rules match, each with its evidence and a first action to take.
✓ Account created
✓ Supabase authorized — read-only
✓ defencecore-prod on the watchlist
✓ First logs normalized
Everything you need to watch one production Supabase project, without enterprise contracts or per-seat pricing.
Defencecore watches Supabase platform logs across authentication, API traffic, Postgres, Storage, Realtime, and Edge Functions, and runs detection rules over all of them together.
No. It is read-only. It detects, explains, and recommends what to investigate, and holds no path that could alter your project — the monitor can never become the incident.
Defencecore is $29 per month with a 7-day trial, covering one monitored Supabase project. That is on top of whatever you pay Supabase; Defencecore does not change your Supabase bill.
Yes. Defencecore reads logs through the Supabase Management API, which works regardless of your plan. It matters more on the free plan, in fact, since free-tier log retention is short and Defencecore keeps the flagged events and incidents after the originals expire.
Not today, and we would rather say so plainly than imply otherwise. Defencecore stores security log metadata and the log lines attached to incidents, so if your Supabase logs contain PHI, that data would reach Defencecore. There is no BAA available yet. If you are handling PHI, talk to us before connecting a project.
Log ingestion starts on the next worker run, within minutes of authorizing Supabase. Whether you see an incident depends on whether anything in your logs matches a rule — a quiet first day means your project is quiet, and the Activity view shows the logs arriving either way.
No. Defencecore translates security events into plain language and shows the evidence behind every finding, so you can act on it without knowing what SQLSTATE 42501 means.
Connect your Supabase project and meet the monitor that never clocks out.
Start for $29 ↗