Xano TRUST CENTER
Xano
Loading…

Certifications

Certification

SOC 3 Type II

Overview

SOC 3 is an independent, general-use attestation report that provides a high-level view of a service organization’s controls relevant to the applicable Trust Services Criteria. Unlike a SOC 2 Type 2 report, a SOC 3 report is designed for broader distribution and does not include the same level of detail in system descriptions, control information, or audit testing results. For Xano as a SaaS platform and data processor, the SOC 3 report provides customers, prospects, and other stakeholders with publicly shareable independent assurance regarding controls within the scope of the examination.

Scope of Xano’s Certification

Our SOC 3 report relates to the IT Consulting Services System and the suitability and operating effectiveness of the controls described throughout the period January 1, 2025, to December 31, 2025. Please review our SOC 3 report below for more details on the scope boundaries and descriptions.

Trust Services Criteria (TSC):

  • Security (Common Criteria)

How Xano Meets Compliance Criteria

Xano maintains a range of policies, procedures, and operational controls to support its compliance obligations and overall security posture. The examples below highlight key elements of our program in relation to this framework, and do not represent a complete list:

  • Implemented access controls, MFA, and BYOD controls on all staff devices
  • Access Control Policy
  • Staff Onboarding & Offboarding Procedure
  • Change Management Procedure
  • Secure Software Development Life Cycle (SSDLC)
  • Critical systems monitoring and alerts
  • Incident Response Procedure
  • Risk Assessment Procedure
  • Management Reviews
  • Backup & restoration testing, third-party penetration testing, third-party network testing
  • Internal Audit Program

Files

100%