Thousands of databases hosted on the developer platform Supabase have been found exposing sensitive personal information to the public internet, according to new research from cybersecurity firm UpGuard, in a finding that adds fresh urgency to concerns about the security of AI-built and rapidly deployed apps.
UpGuard told TechCrunch that it identified around 16,000 databases on which some degree of personal data was exposed while hosted by Supabase, a platform used by web and app developers to store and run databases. The exposed information included publicly accessible names, addresses, phone numbers and user passwords, with a smaller number of passwords and authentication tokens also found in the research.
The scale of the exposure is notable not only for the number of affected databases, but also for the range of projects tied to them. UpGuard said the exposed datasets included private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, and contact information belonging to people who used an immigration and relocation service. One database belonged to an African government's consulate in France, while another was used to intercept text messages for a virtual SIM farm that sent one-time passcodes used to verify online accounts â a technique often associated with scams and phishing operations.
The findings point to a broader problem in the current wave of AI-assisted development, where so-called vibe-coded apps can be created quickly but may be deployed with serious security gaps. AI tools can make it easier than ever to build websites and apps, but the generated code can contain flaws, and developers may not understand the specific configuration steps needed to secure the databases behind them. In practice, that can mean sensitive records are left exposed through basic misconfiguration rather than sophisticated intrusion.
The issue is not new. Over the years, countless breaches have stemmed from improperly configured storage servers, databases and websites, leading to leaks of military emails, immigration and visa applications, classified government files, hundreds of thousands of driver's license scans and children's personal information. What is changing, researchers say, is the speed and scale at which such mistakes are now being made as AI tools accelerate app development and lower the barrier to launching products.
Supabase, which earlier this year reached a $10 billion valuation amid surging demand from developers building on the platform, has become a popular home for startups and independent builders. That popularity has also brought scrutiny. The company has faced criticism over how it handles user security, and there have been widely documented cases of customers misconfiguring or unknowingly exposing their databases to the broader internet, in some cases involving millions of records.
UpGuard said its research was designed to understand the scale of exposed data across the platform. While the majority of the exposed datasets appear to be located in the United States, the firm said the problem is global. The findings build on earlier research that also identified exposed databases hosted on Supabase, including those tied to Y Combinator startups and other popular apps.
Supabase has made changes to its platform over time, including bolstering its platform and user access to databases. But the latest findings suggest that even with improved tooling, the burden of secure configuration still falls heavily on developers and the companies using the service.
When reached for comment, Supabase Chief Information Security Officer Bil Harmer said the company had not seen the research, but maintained that its projects are "secure by default." He described security as a shared responsibility between Supabase and its customers. "We provide secure defaults and tooling, and customers control how their own projects are configured," Harmer said, adding that the company notifies affected customers when security issues are discovered.
"Security at Supabase is never finished. We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely," Harmer said.
The episode underscores a central tension in the AI software boom: the same tools that make it easier to launch products quickly can also make it easier to ship insecure systems at scale. As more developers turn to platforms like Supabase to power vibe-coded apps, the line between rapid innovation and public exposure of private data is becoming increasingly thin.
