Neon Security & compliance

IP allowlist set but public connections not blocked

Part of the Cost & ops health check · fix arrives as a guide

What it is

An IP allow-list is configured but public connections are not blocked, so the allow-list is not actually enforced.

Why it matters

The settings page shows an allow-list, which reads as protection. Connections from outside it still succeed, so the control is present but doing nothing.

How to fix it

Enable the setting that restricts connections to the allow-list. Verify from an address outside it that the connection is refused — an allow-list you have not tested is an assumption.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.