Supabase is a very good product. This page is not about which one has more features, because on features you already know the answer. It is about the one question a Supabase region setting cannot answer, and what happens when your tender, your DPA or your customer's security assessment asks it.
Supabase shipped a Sydney region, and it works. Your rows sit in Australia. But that region runs on AWS, so the company that owns the hardware is American, and Supabase Inc. is a Delaware corporation, so the company that owns the service is American too. Choosing ap-southeast-2 changes where the bytes rest. It does not change who owns them, who runs them, or which government can compel their production.
That distinction is invisible right up until someone asks you about it in writing. A health tender with a sovereignty clause. A government panel's foreign-control question. A bank's third-party risk questionnaire asking you to name every entity in the chain and every jurisdiction that reaches them. At that point a region setting is not an answer, and no amount of product quality makes it one.
WattleDB exists for the teams who have to answer that question. The contracting entity is RR Sols Pty Ltd, ABN 56 672 722 486, an Australian company with no foreign parent and no foreign holding company. The infrastructure is Binary Lane, Australian-owned, in Sydney with backups in Melbourne. The contract is governed by the laws of New South Wales. Every person with production access lives here. There is one entity, one jurisdiction, one answer.
This is not a gap Supabase can close with a release. It is a function of where the company is incorporated.
Not a feature scorecard. These are the lines that appear in vendor security assessments, government panel applications and enterprise DPAs, and the answers are set by corporate structure, not by roadmap.
| The question on the form | WattleDB | Supabase |
|---|---|---|
| Who is the contracting entity? | RR Sols Pty Ltd, ABN 56 672 722 486 | Supabase Inc., Delaware, USA |
| Is there a foreign parent or holding company? | None | Yes, US |
| Who owns the physical infrastructure your data sits on? | Binary Lane, Australian-owned | Amazon Web Services, US-owned |
| Is the provider exposed to US CLOUD Act production orders? | Not directly. WattleDB is an Australian entity with no US parent, so it is not subject to US production orders. Australian providers can be reached only through the Australia–US CLOUD Act treaty path, which is limited to serious crime and runs through Australian legal safeguards. | Yes, as a US-incorporated provider |
| Which law governs the contract, and whose courts hear a dispute? | New South Wales, Australia | United States |
| Where do the people with production access live? | Australia, all of them | Distributed globally |
| Can you name every party in the chain and its jurisdiction? | Yes, in writing | Supabase Inc. + AWS + sub-processors |
| Who answers the phone, under which law? | Australian team, Australian law | Global support |
Every answer above is verifiable from public records and our own DPA and Terms. The US CLOUD Act reaches data in the possession, custody or control of a US-based provider regardless of the country it is stored in, which is why the Supabase column reads the way it does even with the Sydney region selected. No provider anywhere can promise immunity from every legal process, and we don't — we explain the treaty path that can reach an Australian provider, and its limits, in CLOUD Act vs Privacy Act. Nothing here suggests Supabase mishandles data. It is a question of which legal systems can reach it, and how directly.
WattleDB is a data layer, not an application platform. We give you managed PostgreSQL, an auto-generated REST API over PostgREST with JWT and row-level security, S3-compatible object storage, point-in-time recovery, and one-click masked test-database clones so real PII never reaches staging. That is the boundary, and we hold it on purpose.
We do not run your compute. There are no Edge Functions. Hosted authentication and realtime subscriptions are in development and not shipped. If you need serverless functions or realtime in production this quarter, Supabase does that today and we would rather tell you than lose your trust in month two.
The upside of a narrow boundary is that it is describable. When you are the one signing a security questionnaire, every additional service inside the trust boundary is another row you have to explain, another runtime executing code next to your data, another dependency to name. A smaller surface is not a smaller product here. It is the part you can actually defend.
Sovereignty claims are only worth what you can produce when someone checks them. Here is what we will put in front of your compliance team, your bid writer or your customer.
RR Sols Pty Ltd, ABN 56 672 722 486, registered in NSW. No foreign parent, no foreign holding company, verifiable against the ABR. We will put that in a signed statement for your tender.
An Australian-law DPA written against the Privacy Act and the APPs, including breach assistance, sub-processor notice rights, and return and deletion on exit.
The full list, each one named with its jurisdiction and what it touches, available on request, so nobody has to take "Australian-owned" on faith. Outside the data boundary sit our payment provider, our email provider, a fraud-prevention provider used at card entry, an address-lookup service and our certificate authority. None of them receives your database contents.
Contracts governed by the laws of New South Wales, disputes heard in NSW courts. No foreign forum clause, no arbitration in another hemisphere.
Pre-filled answers to the questions that come up in every third-party risk review, so your team is not chasing us for a fortnight mid-procurement. Ask and we will send it.
Run your current stack through the sovereignty checker and see which foreign entities are already in your chain before you talk to anyone, including us.
If that is you, use Supabase. It is a good product and this page is not for you.
pg_dump/pg_restore of your schema and data over WattleDB's DIRECT_URL, then repointing your connection string.One Australian entity, one jurisdiction, one answer when someone asks who owns your data.