Supabase review | Peaceful Media
Hosting & Security

Supabase review

An open-source backend in a box: Postgres database, logins, and file storage without building any of it.

Not an affiliate linksupabase.com
Our take

Is Supabase right for you?

Supabase gives a custom build the pieces that used to take months to assemble: a real Postgres database, user authentication, file storage, and an API over all of it, ready in an afternoon. It’s open source, built on ordinary Postgres rather than a proprietary imitation.

It’s where we start for the database on almost any lean modern build (Next.js, Astro, plain HTML, Python), and it’s close enough to an industry default that most developers you’d hire already know it. Our own business operating system runs on it: we’ve put our own operations on this, not just our clients’.

Two things make it more than a database. First, standard Postgres means the data is portable: you’re not writing your business into a format only one vendor can read. Second, hosts, APIs, and the rest of a modern stack plug into it readily, so the database becomes the hub everything else in a business talks to. That’s a bigger idea than “somewhere to put records,” and it’s why it anchors the lean stack we build on.

The caveat is that it hands you a real database, and real databases reward being treated like one. Somebody has to decide how the data is shaped, what’s indexed, and, most importantly, who can read which rows. Get that last part wrong and you have a security problem, not a bug. It’s a superb foundation with someone thoughtful at the wheel, and more than you need if your site never has to remember anything.

Common questions

Questions about Supabase

What people usually want to know before committing, answered the way we'd answer them on a call.

Do I need to be technical to use Supabase?

Less than you'd expect for something this capable. The interface is approachable enough that a non-technical person can look at their own data, run a query, and understand what's there. That's unusual for a real database, and useful when the person asking about the business isn't the person who built the system. Setting up the schema and access rules properly is still a job for someone who knows what they're doing.

Why Supabase rather than another database?

Because it's become the sensible default, and it's ordinary Postgres underneath, not a proprietary imitation. Your data is portable: you're not writing your business into a format only one vendor can read. Around that sit authentication, file storage, and an API, which would otherwise be weeks of careful work. It also connects to nearly everything, which turns it from a database into the hub a business runs on.

Is the free plan usable for real work?

Yes. It handles a properly complex database perfectly well. You move to a paid tier for scale, backups, and the guarantees a production system should have, not because the free plan can't do the job. For a build that's still proving itself, that's the right shape: it costs nothing until it's carrying something worth paying to protect.

What's the thing to get right?

Row-level access rules, and it's not close. Someone has to decide who can read which rows, and getting that wrong is a security problem, not a bug. The same care applies to how the data is shaped and indexed. With someone thoughtful at the wheel, it's a superb foundation.

Still deciding?

Not sure if Supabase is the right call?

The tool is rarely the hard part; fitting it to what you've already got is. Five minutes with the concierge: honest fit, no pressure, and a real person follows up.