Document
Xano’s environmental, social, and governance practices reflect its approach to responsible operations, workforce conduct, data protection, technology development, and organizational oversight. These practices are supported by internal policies, recurring training, risk management, independent assessments, and management review.
This page provides a high-level overview of selected ESG practices. It is not intended to serve as a formal sustainability report or to represent quantified environmental performance unless expressly stated.
Xano relies on Google Cloud Platform to host Xano-managed services. Google publishes information about its environmental programs, including efforts related to data-center energy efficiency, carbon-free energy, supplier energy performance, water stewardship, and waste reduction. Google also publishes carbon-free energy information for individual Google Cloud regions so organizations can consider environmental characteristics alongside factors such as latency, cost, and data residency.
Google has established a goal to match its electricity consumption with carbon-free energy every hour and in every region by 2030. This is Google’s goal and should not be interpreted as a separate Xano carbon-neutrality or emissions-reduction commitment. Additional information about Google’s environmental and supply-chain initiatives is available through Google’s sustainability reporting, supplier responsibility materials, and Google Cloud sustainability guidance.
Where practical and appropriate, Xano-owned devices are securely wiped and prepared for reuse rather than immediately replaced or discarded. Device handling is subject to applicable security requirements so that reuse does not compromise company, personnel, or customer information. Devices that are no longer suitable for reuse are handled according to applicable disposal and information-security procedures.
Xano seeks to limit unnecessary printing and primarily uses electronic systems for documentation, approvals, records, and internal collaboration. This approach reduces reliance on physical records and also supports Xano’s security objective of limiting the physical storage and handling of sensitive information.
Xano evaluates employment candidates based on qualifications, experience, role requirements, and demonstrated ability to perform the responsibilities of the position. Employment decisions are made without unlawful discrimination based on protected characteristics. Recruitment and interview practices are intended to provide candidates with fair consideration and to identify individuals with the competency appropriate to their role and level of responsibility.
We maintain a harassment-prevention policy designed to promote a professional, respectful, and safe working environment. Staff and consultants are expected to comply with applicable workplace conduct requirements and complete assigned harassment-prevention training.
An anonymous reporting channel is available for personnel and consultants to raise concerns about abuse, misconduct, harassment, policy violations, or other inappropriate activity. Xano also prohibits retaliation against individuals who responsibly report concerns or participate in an investigation in good faith.
Our security and privacy program includes policies and procedures addressing the protection of customer, workforce, and other personal information. Privacy-by-design principles are incorporated into relevant systems and development activities so that privacy and data protection considerations can be evaluated throughout the lifecycle of a service or process.
Data-minimization principles are also applied to limit the collection, use, access, and retention of personal information to what is reasonably necessary for an authorized purpose. Where appropriate and technically feasible, personal information may be anonymized or pseudonymized to reduce privacy risk.
Xano’s AI governance practices require human oversight for internal AI systems and AI-related projects, particularly where sensitive information or material business decisions may be involved. AI systems are used to assist personnel rather than replace human accountability.
AI development activities are subject to testing, review, and human approval before release or operational use. AI-generated outputs are treated as suggestions until they have been evaluated for accuracy, security, privacy, suitability, and compliance.
We maintain an anti-bribery and anti-corruption policy that prohibits personnel from offering, requesting, accepting, or facilitating improper payments or other inappropriate benefits. Personnel are expected to conduct business lawfully, ethically, and in accordance with applicable company policies.
An Acceptable Use Policy governs appropriate use of Xano systems, devices, accounts, applications, and information resources. These requirements are designed to reduce misuse, protect company and customer information, and support responsible use of Xano technology.
We operate an internal audit program consisting of monthly, quarterly, semiannual, and annual activities. These activities are derived from applicable regulatory, contractual, certification, attestation, and internal governance requirements. Internal audit work may include control sampling, documentation review, testing, awareness activities, evidence validation, and follow-up on identified issues. Results are summarized through Xano’s management review process so that relevant leaders can evaluate outstanding matters, track corrective actions, identify opportunities for improvement, and remain informed about the performance of security, privacy, compliance, and operational programs.
Xano undergoes recurring third-party audits and assessments to evaluate applicable aspects of our security, privacy, quality, and compliance programs. Independent assessments provide additional assurance that relevant controls are designed and operating in accordance with the scope and criteria of the applicable audit or certification.
The availability of reports, certificates, and supporting evidence may depend on the type of document, customer eligibility, and whether an NDA or approved security review is required.
All policies and procedures are reviewed and updated at least annually, and may be revised more frequently in response to regulatory, contractual, technical, operational, or risk-related changes.
Staff are required to review and acknowledge Xano’s handbook and policy manual. This process helps us ensure that personnel remain informed of their responsibilities in the security program.
Xano’s business continuity and disaster recovery program is tested annually. The exercise is designed to evaluate recovery procedures, backup integrity, communications, defined responsibilities, and the ability to restore critical services following a significant disruption.
Test outcomes are reviewed to identify lessons learned and opportunities for improvement. Detailed scenarios, recovery configurations, timing data, and internal procedures are not published publicly because they form part of Xano’s confidential resilience and security operations.
We use findings from internal audits, third-party assessments, security testing, risk reviews, training activities, incidents, and management feedback to improve our policies, controls, and operational practices as part of our continuous improvement efforts. Additionally, to better understand the distinct needs of each team, we routinely evaluate continuous improvement opportunities during management review meetings.