What happened
- On September 25, cybersecurity firm UpGuard published a study by Greg Pollock, its director of research, on databases hosted on Supabase, the service many coding assistants use by default to store user data.
- UpGuard identified some 300,000 domains showing signs of using Supabase and queried a table called “users” on each one. In 16,326 databases it found tables readable from the internet, without authentication.
- More than half showed signs of personal data: names, emails, dates of birth, phone numbers, payment data. A smaller fraction exposed passwords or credentials. Among the cases cited is a Canadian immigration service with about 5,000 records and plaintext passwords.
- According to the study, Supabase enables row-level security when a table is created from its interface, but not when it’s created via API, which is the route coding agents use.
Why it matters
- The flaw isn’t in the code the AI writes, but in the step nobody asked it to take. Anyone who builds an app by chatting with an assistant gets something that works and that is also left open. The second part doesn’t show on the screen.
- In Chile, personal data Law 21.719 takes effect on December 1, 2026, and assigns responsibility to whoever processes the data, not to the tool they used. A small business that launched its form with an app generated in an afternoon is, in the eyes of the law, responsible for that database.
- The study itself notes that Europe shows better protection practices and that developing regions leak more. Latin America ends up on the wrong side of that comparison.
The number
16,326 readable databases. That’s what UpGuard found by checking a single table with a common name; the real total may be higher.
Context
Agents acting without supervision are already attacking real systems, and the infrastructure for running models is also piling up flaws, such as SGLang’s four failures in 18 days. This case is simpler and more common: nothing needed to be attacked; the doors were left open.
What’s next
- Supabase hadn’t reviewed the study at the time of publication, according to its chief information security officer, who told TechCrunch it’s a shared responsibility with those who configure the projects.
- Dec 1, 2026: Law 21.719 takes effect in Chile. This note does not constitute legal advice.
Bottom line
Supabase reached a $10 billion valuation this year, driven, according to TechCrunch, by people hosting apps built with AI assistants there. That same user base is the one now showing up in UpGuard’s study.
Sources
- UpGuard, Everything, Everywhere: Systemic Data Exposure in Supabase Apps, September 25, 2026
- TechCrunch, Supabase’s statements on the study, September 25, 2026
Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.



