Neon
Security & compliance
IP allowlist set but public connections not blocked
Part of the Cost & ops health check · fix arrives as a guide
What it is
An IP allow-list is configured but public connections are not blocked, so the allow-list is not actually enforced.
Why it matters
The settings page shows an allow-list, which reads as protection. Connections from outside it still succeed, so the control is present but doing nothing.
How to fix it
Enable the setting that restricts connections to the allow-list. Verify from an address outside it that the connection is refused — an allow-list you have not tested is an assumption.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.