Xano TRUST CENTER
Xano
Loading…

Certifications

Document

Data Privacy & Security

Overview

Xano applies administrative, technical, and organizational safeguards designed to protect customer data throughout its lifecycle, including during storage, transmission, access, backup, restoration, and deletion. These protections include encryption, access controls, monitoring, data classification, secure handling procedures, and documented retention and disposal practices. The specific controls and capabilities available may vary by plan, deployment model, and applicable agreement, and customers remain responsible for how they configure, access, and use data within their own Xano environments.

Access Monitoring

We log and monitor user events, including those that occur internally by employees. Internal user events undergo regular auditing procedures. We employ an Access Control policy combined with Role-Based Access Control (RBAC) mechanisms, restricting access to sensitive information to designated roles.

Privileged accounts are provided only to management authorized to perform system administration tasks. The number of privileged accounts is kept to a minimum. Our regular access audits ensure that each employee is granted precisely the access required for their specific responsibilities.

Physical Security

We apply physical security measures at our primary and secondary office locations to help protect personnel, equipment, and business information. Access to office spaces is controlled, visitor activity is recorded, and we follow a documented Visitor Control Policy. We also track the individuals authorized to hold keys or other physical access credentials for each office location. Both office locations are situated within buildings that use appropriate surveillance and facility security measures.

Xano personnel are also expected to follow clear desk and clear screen requirements to reduce the risk of unauthorized viewing or access to sensitive information in the workplace. We do not print or physically store end-user data at any office location. Customer and end-user information is handled through approved electronic systems,

Backups Enabled

Xano is dedicated to safeguarding your data with a robust framework of disaster recovery procedures and preventative measures. We implement daily backups (every 24 hours), securely stored in the same region as your primary location but within a distinct zone to provide resilience against potential disasters at the main site. On any of our paid plans, Xano maintains full backups of your server instance on a rolling 3-day cycle. In the event of significant problems, you are encouraged to contact our support team for assistance in restoring your instance(s). For Enterprise users, Xano typically provides 30 days of rolling 24-hour backups and a 7-day point-in-time recovery log, offering per-second backup flexibility.

For subscribers of our paid plans, we offer schema versioning for various elements such as database tables, API groups, API endpoints, functions, add-ons, and background tasks. This feature facilitates effortless reversion to prior versions should any errors occur. The extent of version history available varies with the chosen paid plan.

Additionally, for all paid users, we maintain a 24-hour request history for all API requests directed to the Xano instance, encompassing requests that may not accurately align with a designated route. This data is accessible via the Xano interface or through the Xano Metadata API.

Data Classification

Xano classifies internal information and documentation according to four categories: Confidential, Internal, Restricted Access, and Public. Access, handling, storage, and disclosure controls are applied based on the assigned classification and the sensitivity of the information.

This classification framework helps ensure that sensitive information is available only to authorized personnel with an appropriate business need. Detailed classification criteria and internal handling procedures are not published publicly

Encryption

Leveraging Google Cloud Platform (GCP) as our cloud hosting provider, we ensure that your data remains encrypted both at rest and in transit, maintaining the highest level of security.

Encryption-at-rest

Google's robust encryption-at-rest measures encompass the utilization of the advanced AES algorithm. All data stored within the platform is encrypted at the storage level using Data Encryption Keys (DEKs), with a default encryption strength of AES-256, ensuring an exceptionally high level of security. Only a small number of Persistent Disks created before 2015 employ AES-128, which is still considered secure. The choice of AES encryption aligns with the recommendations of the National Institute of Standards and Technology (NIST) for long-term storage, further reinforcing our commitment to meeting customer compliance requirements.

Encryption-in-transit

Google Cloud Platform (GCP) employs various encryption mechanisms to secure data in transit, meaning as it moves from one location to another, such as between user devices and GCP services, or between different services within GCP. The objective of encryption in transit is to protect data from unauthorized access, tampering, or eavesdropping as it traverses networks.

Specifically, GCP typically uses Transport Layer Security (TLS) to encrypt data that is in transit over the network. TLS establishes a secure channel between two systems, ensuring the confidentiality and integrity of the data being exchanged. When customers connect to GCP services, they often do so via HTTPS, which is HTTP over TLS, to ensure data is encrypted in transit. GCP also employs other mechanisms like Virtual Private Cloud (VPC) peering and Interconnect for secure data transit between different cloud resources or between on-premises resources and the cloud. Xano supports TLS 1.2 and 1.3. Please see more information in this report.

For internal communications between GCP services, Google relies on its own highly secure and redundant global network infrastructure. This ensures that data traveling within Google's environment is also encrypted and rigorously secured against intrusion. Xano requires all web communication over HTTPS TLSv1.2 or above.

Data Handling & Deletion

Individual users are responsible for managing and deleting data within their respective Xano instances. Our data retention practices strictly adhere to the guidelines specified in our Privacy Notice, ensuring that only necessary user data is retained by Xano. Upon discontinuing Xano services, you can export all data from your Xano account(s). You maintain complete control over the data utilized within your instances. However, any code associated with your Xano setup is not exportable.

Xano has a formal procedure governing the deletion of sensitive information. Where sensitive data must be temporarily downloaded to an authorized local device for a legitimate business purpose, the activity is documented, and the data is securely deleted when it is no longer required using approved deletion methods designed to make the information irrecoverable.

Deletion Requests

Customers may request deletion assistance by contacting Xano Support. Customers may request:

  • Account deletion, which initiates deletion of the customer’s account and associated account data; or
  • A verified privacy-rights deletion request, such as a request made under the GDPR or CCPA/CPRA.

Privacy-rights requests are subject to identity verification and any applicable legal, contractual, security, fraud-prevention, or retention requirements.

Data Isolation

Xano uses dedicated cloud resources for customers on paid plans to support logical and operational separation between customer environments. Infrastructure configuration and isolation vary by plan and deployment model.

Non-Production Data Handling

Our development and testing practices are designed to avoid unnecessary use of customer, production, personal, or regulated data. Synthetic, anonymized, mocked, or otherwise non-production data is used for testing where appropriate. Additional safeguards are required where sensitive information must be handled for an authorized purpose.

100%