Neon Security & compliance

IP allow-list not scoped to protected branches

Part of the Cost & ops health check · fix arrives as a guide

What it is

The project has an IP allow-list, but it is not scoped to protected branches — so the same rules apply to every branch endpoint.

Why it matters

Neon lets you narrow the allow-list to protected branches only. Which way that toggle should sit depends on your setup, and it is worth deciding rather than inheriting: unscoped applies one policy to production and preview branches alike, while scoping it lifts the restriction from every non-protected branch.

How to fix it

Check the toggle against how your team actually connects. If developers reach preview branches from changing addresses, scoping the allow-list to protected branches keeps production guarded while unblocking them — and should be paired with short-lived branches and separate credentials. If every branch holds data worth restricting, leave it unscoped.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.