PRODSovereign European BaaS platformOpen Dashboard →

Technical & Sovereignty Comparison

Aurabase vs Supabase

Supabase stitches Elixir, Go, TypeScript, and Node service by service. Aurabase unifies the entire platform in Rust, on infrastructure hosted in the European Union and operated by a French company.

At a Glance

Supabase pieces together Elixir, Go, TypeScript, and Node service by service. Aurabase unifies everything in Rust, from the gateway to the database layer. Both run on PostgreSQL, but Aurabase integrates NL2SQL and RAG natively in the backend, whereas Supabase relies on external chat connectors. Regarding sovereignty: Aurabase’s production infrastructure operates in Germany and Finland, run by a French corporation — not an optional EU region bolted onto US cloud infrastructure.

#
Detailed Matrix

Feature Breakdown

CriteriaAurabaseSupabase
Sovereignty & Jurisdiction
Verified production infrastructure in Germany and Finland (Hetzner) · French parent company
Hosted on AWS with region choice (including European regions) · US parent company
Language & Architecture
Unified 100% Rust application core · no garbage collector, predictable execution latency
Heterogeneous multi-service stack (Elixir, Go, TypeScript, Node.js)
Primary Database
Dedicated PostgreSQL 16 per project · native RLS · embedded pgvector and pg_graphql
Managed PostgreSQL · native RLS
Authentication
15 named OAuth providers + unlimited generic OIDC per project
Wide range of OAuth providers (refer to their official documentation)
Edge Functions
Multi-runtime: Deno/TypeScript (V8) and binaries compiled to WASM (real Wasmtime runtime in production)
Deno runtime only
Realtime & CDC
NATS JetStream with server-side column filtering and SSE/WS streaming
Phoenix Channels (Elixir) via PostgreSQL replication slot
Native AI (NL2SQL, RAG)
NL2SQL and RAG built directly into backend · embedded pgvector · 3 native LLM providers (OpenAI, Anthropic, Gemini)
pgvector available · AI orchestration via external chat connectors (ChatGPT App, Claude)
MCP Server
Official MCP server (@aurabase/mcp-server) for Cursor, Claude Code, and Windsurf
Third-party community MCP integrations
Compatibility & Migration
Compatible with PostgREST and standard pg_dump/pg_restore
Native PostgREST format standard

Also evaluating a NoSQL database? See our comparison with Firebase. Other open source alternatives: Aurabase vs Appwrite and Aurabase vs PocketBase. Interested in a proprietary reactive backend? See Aurabase vs Convex. To compare all criteria at once, our 2026 BaaS comparison matrix and our BaaS selection FAQ cover the full landscape.

#
Engineering

Architecture — heterogeneous stack vs unified Rust core

A single language and runtime changes the integration bug surface and operational consistency, not just perceived performance. Supabase pieces together microservices written across multiple different languages (PostgREST in Haskell, GoTrue in Go, Realtime in Elixir, Storage in Node.js, Functions in Deno). In contrast, Aurabase’s 12 services share the same internal crates — aura-core, aura-crypto, aura-db-adapters, aura-telemetry — written in the same language.

  • Zero Garbage Collector pauses: Rust has no garbage collector, eliminating unpredictable runtime pauses under heavy concurrent loads.
  • Reduced memory footprint: without parallel managed runtimes to keep alive (JVM, Node, BEAM), allocated memory directly serves the PostgreSQL cache and query execution.
  • NATS JetStream for Realtime: an event-driven messaging architecture engineered for horizontal scale, rather than an Elixir channel per connection.
#
Data

Database — dedicated PostgreSQL 16

Each Aurabase project runs on a dedicated PostgreSQL 16 instance: no multi-tenant engine shared between projects. Supabase also offers managed PostgreSQL with native RLS — on this specific point, both platforms are matched.

Aurabase’s tenant Postgres image embeds pgvector 0.8.6 and pg_graphql. A nuance to keep in mind: pgvector is already present in the upstream standard CNPG image — it is not an Aurabase addition. pg_graphql, on the other hand, is a third-party extension developed by the Supabase team themselves, which Aurabase packages natively into its tenant image. Neither is an in-house Aurabase creation; what changes is that they arrive preinstalled without manual configuration.

#
Auth

Authentication — 15 OAuth providers + generic OIDC

Aurabase supports 15 named OAuth providers — Apple, Bitbucket, Discord, Facebook, Figma, GitHub, Google, Kakao, Microsoft, Notion, Snapchat, Spotify, Twitch, Twitter, and Zoom — plus unlimited generic OIDC providers per project (convention oidc:<name>, for any OpenID Connect discovery identity provider, like Okta). LinkedIn and GitLab are not among these named providers today.

Supabase also covers a wide range of OAuth providers. The exact list evolves regularly: refer to their official documentation for up-to-date details rather than a static count here.

#
Artificial Intelligence

Native AI — NL2SQL and RAG built into the backend

Aurabase integrates NL2SQL and RAG directly into the backend — not as afterthoughts or external connectors. The NL2SQL engine translates a natural language question into SQL, validates its syntax, and caps query scope before execution. RAG leverages pgvector, already embedded in the tenant Postgres image, with HNSW vector indexing.

Three LLM providers have dedicated native clients: OpenAI, Anthropic (Claude), and Google Gemini. Mistral, Scaleway AI, and Ollama remain accessible via an OpenAI-compatible endpoint — a nuance that matters if you depend specifically on one of these providers rather than one of the three native clients.

Supabase took a different direction: an official Claude connector (launched in February 2026) and an official ChatGPT app (launched in spring 2026) let you query a Supabase database from external conversational interfaces. This is an external orchestration approach, not an NL2SQL engine built into the backend itself.

See complete details on native NL2SQL and RAG
#
Runtime

Edge Functions — WASM/Wasmtime vs Deno alone

Aurabase offers two runtimes for Edge Functions: Deno/TypeScript (V8), close to the Supabase experience, and binaries compiled in Rust to WebAssembly, executed by a real Wasmtime runtime — a production dependency of the service, not an internal experiment.

No published cold start figures
The WASM/Wasmtime runtime is deployed and runs in production, but no reproducible cold start benchmark is published in the repository to date. Any performance claims on this point await a timestamped, published methodology rather than marketing figures.
#
Legal & Compliance

Data Sovereignty and the CLOUD Act

The fundamental distinction relies on two cumulative conditions: physical hosting location AND the legal jurisdiction of the operating parent company. Checking an "EU" box in an administrative console is not sufficient on its own.

Aurabase: infrastructure and parent company in the EU

Production infrastructure runs in Germany (Nuremberg, Falkenstein) and Finland (Helsinki) with Hetzner — no other location is verified to date. Aurabase SAS, the operating company, is a French corporation headquartered in Paris.

Supabase: selected region, US jurisdiction

Supabase lets users select an AWS hosting region, including European regions. However, the selected region does not alter the corporate nationality of the company holding your data: Supabase remains a US entity subject to the US CLOUD Act regime regardless of the selected region.

Learn more: GDPR and CLOUD Act compliance
#
Ecosystem

SDK and Ecosystem — parity and real differences

Aurabase’s JavaScript SDK is distributed across 10 scoped npm packages under @aurabase/* — aurabase-js, core, auth, db, storage, realtime, ai, functions, notifications, and gen — all published and installable.

Python, Dart, and Rust SDKs exist within the project repository, but none of the three is yet published to its respective registry (PyPI, pub.dev, crates.io — verified live across all three): they can currently only be installed as Git repository dependencies, not via a simple pip install, pub add, or cargo add.

npm naming trap
An unscoped package aurabase-js (without the @aurabase/ prefix) exists separately on the npm registry. Its connection to the Aurabase project is not confirmed — only install the scoped version @aurabase/aurabase-js.

All Aurabase tiers, including the free plan, are detailed on the Aurabase pricing page.

#
Seamless Transition

How to migrate from Supabase to Aurabase

Aurabase is built on standard PostgreSQL 16 and a PostgREST-compatible API: migrating does not require heavy application code rewrites or RLS policy changes.

# 1. Export schema and data from Supabase
pg_dump "$SUPABASE_DB_URL" --schema=public --no-owner --no-acl --format=custom -f supabase-dump.pgdump
# 2. Restore into Aurabase project (search_path=project_<id> required)
pg_restore --no-owner --no-acl -d "$AURA_DB_URL" supabase-dump.pgdump
Read the complete step-by-step migration guide
#
Frequently Asked Questions

FAQ

Can I migrate a Supabase project to Aurabase without rewriting RLS policies?+
Yes. Aurabase uses standard PostgreSQL 16 with the exact same RLS syntax: auth.uid(), auth.role() and your existing SQL policies work as-is. The complete migration guide details pg_dump export, user migration, and SDK replacement.
Is Aurabase open source, like Supabase?+
Aurabase’s Rust workspace (Cargo.toml) and @aurabase/* JavaScript SDK packages are published under the MIT license. The source code is inspectable and reusable under these terms, matching Supabase’s open source stance.
Does Supabase offer an EU region?+
Yes: Supabase allows selecting hosting regions including European zones. However, this does not change the corporate jurisdiction of the entity holding your data — Supabase remains a US entity subject to the CLOUD Act regardless of selected region, whereas Aurabase SAS is a French entity operating infrastructure in Germany and Finland.

TAKE ACTION

Switch to a sovereign, unified Postgres backend

Get started in minutes. Zero vendor lock-in, hosted in Europe.

No credit card required · 500 MB free · 50,000 MAU