Xano TRUST CENTER
Xano
Loading…

Certifications

Document

Access Controls

Overview

Xano maintains access control practices designed to protect customer data, platform systems, and internal business resources from unauthorized access. Access controls are a core part of Xano’s security program and are designed to support appropriate authorization, limited access, secure authentication, monitoring, and accountability across Xano-managed systems.

Xano’s approach to access control is based on the principle that access should be granted only where there is a valid business need, approved purpose, and appropriate authorization. Access control responsibilities are shared between Xano and customers. Xano manages access to internal systems, Xano-operated systems and services, while customers are responsible for configuring and managing access within their own Xano workspaces, applications, APIs, databases, integrations, and end-user environments. Looking for access control features to enable in your Xano workspace? Check out our documentation site.

Secure Data Access Procedure (SDAP)

Xano maintains a Secure Data Access Procedure, or SDAP, to govern how Xano personnel may access customer environments or customer data when access is required for authorized business purposes. This may include scenarios such as customer-authorized support, troubleshooting, security review, operational support, or compliance with applicable legal obligations.

Xano limits access to customer environments and customer data to authorized personnel with a legitimate business need. Access is expected to be appropriate to the purpose of the request and handled in accordance with Xano’s internal security, privacy, and confidentiality requirements. Customers should review Xano’s Privacy Notice, Terms and Conditions, and contractual agreements for more information about when access may occur and how customer data is handled. The following diagram is an overview of the steps taken by both users and staff before account data can be accessed*.

1.00

*Please note that while this procedure is generally applicable, Xano cannot guarantee strict adherence in the event of legal requests.

Principle of Least Privilege

Xano applies the principle of least privilege to access management. This means access to internal and Xano-controlled systems, tools, and data is intended to be limited to the minimum level necessary for an authorized role or business purpose. Access is not intended to be broader than needed to perform approved duties. Least privilege supports Xano’s ability to reduce unnecessary access, separate responsibilities where appropriate, and limit exposure of customer data and sensitive systems.

Authentication and Password Security

Xano maintains authentication and password security practices designed to reduce the risk of unauthorized access to Xano-managed systems. These practices include requirements for strong authentication, secure password handling, and additional authentication safeguards where appropriate. For all critical systems that store sensitive data, additional authentication features, such as multi-factor or IAM authentication, must be enabled where possible.

The following requirements are set out in Xano’s Password Management Policy:

  • Passwords to critical systems must be rotated every 90 days
  • Passwords are tracked to prevent reuse
  • All staff are required to use strong passwords that meet our policy’s requirements. These requirements are updated regularly to reflect industry best practices and compliance requirements.
  • Passwords must be securely stored in Xano’s internal password management system, and must not be revealed to anyone
  • Passwords cannot be written down or stored in unprotected locations or systems
  • If a temporary password is issued, upon the next successful login, the password must be changed
  • Xano relies on session locks after several failed login attempts through core systems

Role-Based Access & Workspace Permissions

Xano maintains internal access management procedures designed to control who can access Xano-managed systems and other critical internal systems, as well as what actions authorized personnel may perform. RBAC permissions vary per system we use and by the security features available to us. In general, role-based access controls, administrative permissions, and authentication safeguards are applied based on job responsibilities, business need, and system sensitivity.

Customer Support Access

Xano personnel do not routinely access customer workspaces or customer application data except where access is needed for authorized purposes. In many cases, support access is initiated by a customer request and enabled through customer-controlled workspace settings that permit Xano support personnel to assist with troubleshooting or account-related inquiries. Our customer support team utilizes various models of Anthropic's Claude to assist with requests. These internally developed Claude systems digest only the minimum amount of data needed in the context of the submitted support ticket, but may still process end-user data. You can request that your support agent not use artificial intelligence to assist with your request. Please note that this information must be provided at the start of each conversation with our customer support team and may result in slower response and resolution times.

Logging & Monitoring

Xano maintains logging and monitoring practices for Xano-managed systems to support security, operational oversight, troubleshooting, and investigation activities. These practices include maintaining detailed logs of actions performed through the Xano administrative interface, including access to customer accounts and authorized impersonation activities. These logs are regularly reviewed to help ensure that access to customer data aligns with legitimate business requirements and to identify any potentially suspicious or unauthorized activity. In addition, as part of Xano’s internal audit program, we conduct broader periodic reviews of access controls, role-based access configurations, and other security features across critical systems to ensure alignment with internal policies.

Access Revocation

Xano follows offboarding procedures designed to remove access when it is no longer appropriate. Upon a staff member’s departure, access to critical systems is removed within 24 hours of offboarding. This process supports Xano’s broader access control program by helping ensure that former personnel no longer retain access to Xano-managed systems, internal resources, or other sensitive environments following their departure.

100%