Document
We maintain security practices designed to protect the infrastructure supporting Xano-managed services. These practices include infrastructure isolation, regional hosting options, monitoring, access controls, resilience measures, and security oversight appropriate to the applicable plan and deployment model. Unless otherwise defined in an Enterprise or Custom agreement, Xano-managed services are hosted on Google Cloud Platform (GCP). Xano uses managed cloud infrastructure, including Kubernetes-based components, to operate and scale the platform.
Paid customers select an available hosting region when creating their Xano instance. This selection determines the primary region in which the instance is hosted, subject to the capabilities and terms of the applicable plan. Customers should select a region that supports their performance, business, contractual, and regulatory requirements.
Xano uses a single-tenant infrastructure model for all paid plans. Each instance (excluding our free plan) is provisioned with dedicated cloud resources and has its own configuration, helping provide separation between customer environments. This architecture is designed to limit the effect that an availability or resource issue affecting one customer instance may have on other instances. However, shared cloud provider services, regional events, dependencies, or broader platform components may still affect multiple customers in certain circumstances.
Xano uses Kubernetes to manage the deployment, operation, and scaling of services within our managed cloud environments. We maintain security and operational controls for these clusters; however, specific architecture and administrative details are not publicly disclosed to reduce the risk of misuse or attempted evasion.
Please note that infrastructure management responsibilities differ between our managed and self-hosted plans; always consult your specific contractual agreement with us to understand these details.
Across Xano-managed infrastructure, monitoring and notification capabilities provide visibility into the health and security of Xano-managed infrastructure. Notifications are configured for significant operational and security-related conditions, such as service interruptions, resource or computing limits, and other events that may require investigation or response. These capabilities support our operational monitoring, incident response, capacity management, and service resilience practices. Specific alert thresholds, detection logic, response procedures, and internal escalation paths are not published publicly to reduce the risk of misuse or attempted evasion.
Because paid-plan customer instances use dedicated infrastructure, customers seeking additional instance-specific distributed denial-of-service protection may enable the Google Cloud Armor add-on on their individual Xano instance. Availability, configuration, and pricing for this add-on vary. Customers can contact Xano Support for more details.
Xano incorporates robust perimeter firewall capabilities, thanks to our utilization of Google Cloud Platform (GCP). By leveraging GCP's advanced network security features, including VPC Service Controls, we have established secure perimeters around our cloud resources. This implementation not only enhances the overall security of our product offerings but also ensures stringent data protection and compliance with industry standards. Our commitment to leveraging GCP's infrastructure allows us to provide a highly secure and reliable service to our customers, safeguarding their data with cutting-edge perimeter security measures inherent in the Google Cloud ecosystem.
Our latest Network Diagram is available upon request below.
Certain Custom or Enterprise plan customers may choose to have Xano configured within a customer-controlled cloud environment. Responsibilities for the initial setup, cloud account, infrastructure, access management, network configuration, monitoring, maintenance, security, and ongoing operation may differ from those of a fully Xano-managed deployment. Applicable responsibilities are defined in the corresponding Master Services Agreement, order form, implementation documentation, or other contractual materials. Customers using these deployment models should review those documents to understand which cloud and security responsibilities are assigned to Xano and which remain with the customer.