SOC 2 Type 2 compliant
Independently assessed controls for Supabase's hosted platform.
Read Supabase's SOC 2 explanationMatchAudit is designed to help teams preserve sensitive screening evidence, reviewer rationale and decision history. This page explains the infrastructure we use, the controls MatchAudit is responsible for and the boundaries of our providers' certifications.
MatchAudit uses Supabase for core managed authentication, PostgreSQL database, and private evidence-file storage infrastructure. Supabase's hosted platform is SOC 2 Type 2 compliant and ISO/IEC 27001:2022 certified.
Independently assessed controls for Supabase's hosted platform.
Read Supabase's SOC 2 explanationSupabase's information security management system is certified to the international ISO/IEC 27001:2022 standard.
Read Supabase's ISO informationSee also Supabase's official security page.
Supabase is responsible for controls within its hosted platform. MatchAudit remains responsible for how the application is designed and configured, including application access, tenant separation, permissions, data handling and operational security.
The Free AMLR Readiness Check processes uploaded bytes and extracted text inside the request only. It creates no diagnostic database row or storage object, and provider calls disable model-side storage.
AI can classify documents and extract cited facts. Versioned deterministic rules calculate every diagnostic status and score; the model cannot approve, reject, set risk, or make a compliance decision.
MatchAudit uses Supabase Auth helpers across login, signup, reset-password, invite, dashboard and route-handler flows.
Evidence Hub records, files, subjects, matters, decisions and audit events are scoped to organization membership and enforced by PostgreSQL Row Level Security policies at the database layer, not application filters alone. Membership supports a user belonging to more than one organization, verified by automated tests that run against a real PostgreSQL database.
Evidence Hub uploads use a private Supabase Storage bucket. Server routes validate the organization context before storing file metadata or creating a signed download URL.
Uploaded Evidence Hub files are hashed with SHA-256 and stored with immutable file metadata such as bucket, path, file name, size, MIME type and uploader.
Evidence-file download routes check Evidence Hub access and organization membership before creating a short-lived signed URL.
Evidence Hub routes create audit-event rows for actions such as file uploads and retention expiry where those workflows are implemented.
Contact MatchAudit if your organisation needs to review infrastructure, data handling, access controls, retention or subprocessor information before using the service.