Built for Supabase

Your Supabase project
just got a security team.

Defencecore reads your Supabase logs, catches the attacks and misconfigurations hiding in them, and shows you the evidence behind every finding.

AISBDC

2-minute setup
Read-only by default

defencecore
Monitor online
MS
OPEN INCIDENTS

What your monitor caught.

LIVE
critical412 events

Credential stuffing against email sign-in

412 failed sign-ins in 22 minutes from 14 addresses, all against three known account emails. Rate limiting held and no session was issued.

EVIDENCEauth.log level=warn msg="invalid_grant" email="[email protected]" ip=83.142.11.204 attempts=57auth.log level=info msg="rate_limit_exceeded" window=60s rejected=188auth.log level=info msg="session_created" count=0 window=30m
Force a password reset on the three targeted accounts.
EVERY LOG SUPABASE WRITES
Auth
Postgres
API
Storage
Realtime
Edge Functions

You ship fast.
Attackers don't wait.

Traditional security tools assume you have a security team, a SIEM, and someone on call. Defencecore assumes you have a product to ship and nobody watching the logs.

See how it works

Security without
the security degree.

Defencecore turns noisy platform logs into clear answers your whole team can understand.

01

Always watching

Continuous Supabase log monitoring catches suspicious auth, API, database, and Edge Function activity.

••
02

Plain English, not SQLSTATE

Every incident says what happened, which project it hit, and what to do first — no log-query language to learn.

03

Evidence, not panic

Every incident carries its timeline, the correlated entities, and the raw log lines the rule matched.

READ ONLY
04

Safe by design

Defencecore can read findings and explain risk, but it cannot change your production project.

From zero to protected
in about two minutes.

  1. 01

    Create your account

    Email and password, or a magic link. No card required for the trial.

  2. 02

    Connect Supabase

    Choose your production project and authorize read-only log access.

  3. 03

    Watch the dashboard

    Incidents open as rules match, each with its evidence and a first action to take.

SETUPABOUT TWO MINUTES

Account created

Supabase authorized — read-only

defencecore-prod on the watchlist

First logs normalized

Your security monitor is online

One plan.
No security tax.

Everything you need to watch one production Supabase project, without enterprise contracts or per-seat pricing.

DEFENCECORE PROBEST FOR SMALL TEAMS
$29/ month
  • One production Supabase project
  • Continuous security monitoring
  • Seven-day incident history
  • Every incident with full evidence
  • Row Level Security and key-exposure rules
Start monitoring 7-day trial · Cancel anytime

The important stuff.

What does Defencecore monitor?+

Defencecore watches Supabase platform logs across authentication, API traffic, Postgres, Storage, Realtime, and Edge Functions, and runs detection rules over all of them together.

Can Defencecore change my production database?+

No. It is read-only. It detects, explains, and recommends what to investigate, and holds no path that could alter your project — the monitor can never become the incident.

What does Supabase security monitoring cost?+

Defencecore is $29 per month with a 7-day trial, covering one monitored Supabase project. That is on top of whatever you pay Supabase; Defencecore does not change your Supabase bill.

Does it work with a free Supabase project?+

Yes. Defencecore reads logs through the Supabase Management API, which works regardless of your plan. It matters more on the free plan, in fact, since free-tier log retention is short and Defencecore keeps the flagged events and incidents after the originals expire.

Is Defencecore HIPAA compliant?+

Not today, and we would rather say so plainly than imply otherwise. Defencecore stores security log metadata and the log lines attached to incidents, so if your Supabase logs contain PHI, that data would reach Defencecore. There is no BAA available yet. If you are handling PHI, talk to us before connecting a project.

How quickly will I see an incident after connecting?+

Log ingestion starts on the next worker run, within minutes of authorizing Supabase. Whether you see an incident depends on whether anything in your logs matches a rule — a quiet first day means your project is quiet, and the Activity view shows the logs arriving either way.

Do I need to be a security expert?+

No. Defencecore translates security events into plain language and shows the evidence behind every finding, so you can act on it without knowing what SQLSTATE 42501 means.

Your monitor is ready

Ship at AI speed.
Stay in control.

Connect your Supabase project and meet the monitor that never clocks out.

Start for $29