Certification
The Data Privacy Framework is a U.S. Department of Commerce-administered cross-border data transfer mechanism that enables participating U.S. organizations to receive eligible personal data from the EU, UK, and Switzerland under a recognized privacy framework; it is not the same type of third-party audit certification as ISO or SOC. For Xano as a SaaS platform and data processor, participation in DPF signals a formal public commitment to the principles governing how transferred personal data is handled, including requirements related to notice, choice, accountability, security, and recourse. For customers as data controllers, DPF participation can support their assessment of lawful transatlantic data transfer options and provide additional comfort that their U.S.-based service provider has committed to an established privacy framework for applicable transfers.
Self-certification for the protection of data transfers between EEA, UK, and Switzerland to the United States.
Xano maintains a range of policies, procedures, and operational controls to support its compliance obligations and overall security posture. The examples below highlight key elements of our program in relation to this framework, and do not represent a complete list:
The status of Xano’s DPF participation can be viewed at https://www.dataprivacyframework.gov/list.