Document
Our documented policies, procedures, plans, and other supporting documents form the foundation of Xano’s security program. Together, this documentation establishes expectations for protecting information, managing risk, overseeing personnel and third parties, developing and operating our services, responding to incidents, and continually improving our program.
Policies and procedures are reviewed at least annually and may be updated more frequently to reflect changes in technology, business operations, legal requirements, contractual obligations, identified risks, audit results, and industry practices. Staff are required to review and acknowledge the policies applicable to their roles.
The summaries below provide a high-level overview of our policies and procedures within our security program. This page does not represent an exhaustive list of all of our security program documentation, and is intended to demonstrate the maturity of our program. These summaries intentionally omit confidential configurations, internal system names, control thresholds, testing criteria, and other details to protect that information from misuse.
Defines how personnel may use company systems, devices, accounts, applications, cloud services, and AI tools. It prohibits unauthorized activity, credential sharing, circumvention of security safeguards, and handling sensitive information through unapproved methods.
Defines how access to Xano-managed systems and information is requested, approved, provisioned, reviewed, modified, and revoked. Access is based on role, business need, least privilege, and appropriate authentication safeguards.
Operationalizes access-control requirements through documented workflows for granting, reviewing, changing, and removing access. Additional controls apply to privileged or sensitive systems.
Establishes requirements for securely storing, using, tracking, rotating, and revoking API keys used in business-critical systems and integrations. It also requires validation of affected services following key changes.
Governs the secure, ethical, and privacy-conscious use of approved AI tools. Human oversight is required, sensitive-data use is restricted, and AI-generated outputs must be reviewed before they are relied upon or shared externally.
Defines how security-relevant activity is logged, reviewed, retained, and escalated across Xano-managed systems. Logging supports accountability, incident response, investigations, and audit evidence.
Defines requirements for backing up and restoring critical systems and information. Recovery capabilities are reviewed and tested periodically to support availability, resilience, and applicable obligations.
Establishes pre-employment screening requirements where legally permitted and appropriate to the role. Screening is conducted in accordance with applicable employment, privacy, and fairness requirements.
Sets security and approval requirements for personally owned devices used to access Xano systems or information. Required safeguards depend on the device, role, systems accessed, and data sensitivity.
Defines how essential business operations may be sustained or restored following a significant disruption. It addresses critical services, communication, dependencies, recovery priorities, and organizational coordination.
Provides a structured method for identifying critical services, dependencies, and the potential consequences of disruption. Results inform continuity planning, recovery priorities, and resource requirements.
Establishes expectations for managing strategic customer and partner relationships. It addresses service reviews, contractual alignment, formal complaints, performance, and ongoing communication.
Defines how infrastructure and service capacity are managed. The process considers current usage, expected growth, service changes, and applicable availability requirements.
Establishes a controlled process for documenting, assessing, testing, approving, implementing, and reviewing significant internal changes and changes to Xano offerings. Change records support risk evaluation, traceability, rollback planning, and accountability.
Requires personnel to secure screens and work areas when unattended and to limit physical or visual exposure of sensitive information. The requirements apply to office and remote work environments.
Defines safeguards for protecting information transmitted through networks, remote-access methods, email, collaboration platforms, and other communication channels. Approved tools and appropriate encryption are required based on sensitivity.
Governs the review and publication of content through official Xano channels. It is designed to protect confidential information, support accuracy, and maintain alignment with legal and organizational requirements.
Defines how audit results, incidents, risk reviews, testing, feedback, and operational observations are used to improve controls and processes. Corrective actions and significant issues are documented, tracked, and reviewed.
Outlines Xano’s approach to ethical business conduct, environmental considerations, workforce practices, privacy, and governance. It provides a framework for responsible organizational decision-making.
Establishes requirements for the appropriate use and management of encryption and related cryptographic safeguards. It addresses data protection in storage, transmission, endpoints, and supported systems.
Defines how customer complaints are received, documented, assessed, investigated, escalated, and resolved. Trends and recurring issues may be further reviewed to identify broader improvements.
Sets expectations for the customer support team or other staff who may access customer environments or data during support activities. It addresses authorized access, appropriate handling, escalation, and professional conduct.
Defines information-classification categories and the handling, access, storage, transmission, and disclosure requirements associated with each level. Controls are applied according to sensitivity and potential impact.
Establishes requirements for retaining, deleting, anonymizing, and securely disposing of information throughout its lifecycle. Legal, contractual, operational, and privacy obligations are considered when determining retention and deletion.
Defines the operational steps for processing account-deletion and verified privacy-related deletion requests. It addresses request validation, system removal, applicable retention exceptions, and secure disposal.
Defines how privacy-related complaints are received, investigated, documented, and resolved. The process includes escalation and corrective action where appropriate.
Supports verified requests involving access, correction, deletion, and other applicable privacy rights. Requests are assessed according to jurisdiction, identity verification, Xano’s processing role, and permitted legal exceptions.
Governs internally sponsored development projects, exploratory work, and public releases associated with Xano. It addresses approval, security, licensing, intellectual property, compliance, and launch readiness.
Defines how company-owned devices are requested, approved, configured, secured, returned, and sanitized. Devices must meet applicable security requirements before accessing sensitive systems.
Defines how critical systems are restored following significant infrastructure or system disruption. Recovery capabilities are tested periodically, and outcomes are reviewed for improvement.
Establishes a fair process for addressing violations of security, privacy, acceptable-use, or workplace requirements. Actions are based on the nature and severity of the issue.
Defines the process for handling unresolved privacy complaints covered by the Data Privacy Framework through an independent dispute-resolution mechanism. It applies to eligible personal information for which Xano acts as a controller.
Sets expectations for maintaining a safe and professional workplace free from unlawful substance use. Requirements are applied in accordance with applicable law and may include additional standards for sensitive roles.
Defines the security, documentation, access provisioning, and training requirements that apply when staff join Xano, as well as the offboarding steps when staff leaves Xano. Access is provisioned based on role and promptly removed following departure.
Requires access and responsibilities to be reviewed when personnel change roles. Permissions are adjusted to remain aligned with current duties and least-privilege principles.
Defines the organizational and security steps associated with voluntary and involuntary separations. It addresses access removal, company intellectual property, documentation, and applicable legal requirements.
Defines requirements for protecting sensitive information through encryption at rest and in transit. It also addresses encryption expectations for devices, communications, and approved data-handling methods.
Sets expectations for lawful, ethical, and professional conduct. It addresses conflicts of interest, confidentiality, responsible use of company resources, respectful behavior, and reporting concerns to appropriate management.
Defines how customer and third-party audit requests are reviewed, approved, scoped, and fulfilled. Evidence is provided through controlled channels in accordance with contractual and confidentiality requirements.
Defines how data and communications are managed across Xano’s critical systems. It addresses network segmentation, permitted flows, filtering, access restrictions, and periodic review.
Defines how legal and government requests for information are validated, reviewed, documented, and fulfilled. The process is designed to limit disclosure to information appropriately covered by a valid request.
Defines the steps used to recruit, evaluate, select, screen, and onboard personnel. It includes role-appropriate interviews, required documentation, background screening, training, and controlled access provisioning.
Defines how authorized customer-account access and impersonation activity is reviewed for legitimacy and appropriate business purpose. Suspicious or unsupported activity is escalated for investigation.
Defines how operational incidents and service requests are categorized, assigned, tracked, escalated, communicated, and resolved. Security-related events are directed to appropriate response personnel.
Defines how security-related information is communicated to internal and external stakeholders. It addresses policy updates, incidents, audits, regulatory matters, and approved communication channels.
Defines how security incidents are detected, assessed, contained, investigated, remediated, communicated, and reviewed. The process includes post-incident analysis and corrective actions.
Documents measurable information-security objectives and the activities used to achieve them. Progress is reviewed through management oversight and adjusted as business and risk priorities change.
Establishes the overall framework for protecting the confidentiality, integrity, and availability of information. It provides the foundation for Xano’s security governance, objectives, controls, and continual-improvement activities.
Requires internally developed applications and automations to undergo security and risk review proportionate to their intended use and the information they process. Material changes are also subject to change-management requirements.
Defines recurring internal audit activities used to evaluate whether controls and processes continue to operate as intended. The program includes sampling, testing, documentation review, evidence validation, and corrective-action follow-up.
Supports the identification, tracking, and management of applicable legal, regulatory, certification, attestation, and contractual obligations. Incorporates relevant requirements into policies, controls, and compliance priorities.
Defines security requirements for mobile devices used to access Xano systems or information. It addresses authentication, updates, screen protection, notifications, connectivity, and appropriate data handling.
Sets expectations for professional conduct, workspace use, security awareness, visitor handling, and information protection at Xano office locations. This policy complements broader physical and workplace-security requirements.
Defines the operational steps for completing required agreements, screening, training, endpoint controls, and role-based access before new personnel begin work. Access is provisioned only after applicable prerequisites are satisfied.
Encourages personnel to raise concerns relating to work, conduct, workload, or wellbeing through available reporting channels. It supports respectful handling, confidentiality, and non-retaliation.
Defines day-to-day requirements for secure system operation. It addresses access, malware prevention, software management, backups, monitoring, maintenance, and controlled administrative activity.
Establishes requirements for lawful and responsible outbound marketing. It addresses permitted outreach, transparency, opt-out handling, suppression practices, and regional privacy requirements.
Defines eligibility, accrual, use, and administration of paid time off and related leave benefits. It supports consistent workforce management and operational planning.
Defines available parental-leave benefits and related eligibility, administration, and coordination with applicable legal programs. It supports workforce wellbeing and continuity.
Establishes requirements for creating, storing, protecting, and managing passwords and other authentication credentials. It also addresses account protection, reuse, sharing, and approved password-management methods.
Defines how software and security updates are identified, prioritized, tested, deployed, verified, and monitored. The process is designed to address known risks while reducing the chance of unintended impact.
Defines how employee performance and competency are reviewed. Evaluations support accountability, development, role alignment, and consistent management decisions.
Defines how personnel are trained to identify, report, and respond to phishing and related social-engineering threats. It also establishes escalation and response expectations following suspected exposure.
Defines how exceptions to established policies are requested, assessed, approved, documented, and reviewed. Exceptions are intended to be controlled, justified, time-bound, and subject to risk oversight.
Establishes the principles and requirements governing personal-information processing. It addresses transparency, lawful use, privacy by design, data minimization, individual rights, security, retention, and vendor oversight.
Defines Xano’s commitment to consistent service delivery, customer requirements, risk-based decision-making, process oversight, and continual improvement. Quality objectives are integrated with security, privacy, and operational obligations.
Defines how business, security, compliance, privacy, and operational records are retained, protected, archived, and disposed of. Controls apply throughout the record lifecycle.
Defines how enterprise customers may export data and transition away from Xano services. It addresses customer control, account closure, retention, deletion, and orderly offboarding.
Defines the methodology used to identify, assess, score, treat, document, and review risks. Treatment options include mitigation, avoidance, transfer, and acceptance, with elevated risks requiring additional oversight from top management.
Establishes the overall framework for managing security, privacy, operational, vendor, compliance, and technology risks. It governs risk ownership, treatment, monitoring, review, and management approval.
Defines how system changes may be safely reversed when deployment issues or security events occur. It addresses pre-deployment planning, restoration, authorization, validation, and post-event review.
Integrates security, privacy, quality, and compliance considerations throughout planning, design, development, review, testing, release, and post-deployment activities. AI-assisted outputs remain subject to human review and standard development controls.
Provides a structured method for evaluating the potential impact of security risks on systems, information, operations, finances, and compliance obligations. Results inform risk treatment and security priorities.
Prohibits sexual harassment and related inappropriate conduct. It provides reporting channels, investigation expectations, confidentiality protections, and non-retaliation safeguards.
Requires software to be evaluated, approved, licensed, and used within its authorized scope. Unauthorized installation, use, or removal is restricted.
Provides managers with guidance for responding when personnel raise concerns relating to stress, workload, wellbeing, or workplace conditions. It addresses listening, practical support, escalation, documentation, and follow-up.
Defines how subcontractors are evaluated, approved, contracted, monitored, and reviewed. Requirements are proportionate to the services performed, associated risks, and information or systems involved.
Defines how third-party suppliers are evaluated and overseen throughout the relationship lifecycle. Reviews consider service criticality, security, privacy, contractual obligations, performance, and data-processing activities.
Defines requirements for authorized, documented, and controlled maintenance of systems, applications, infrastructure, and devices. Maintenance activities are planned and verified to reduce security and availability risks.
Defines how devices and storage media are securely wiped, reused, recycled, or destroyed. Sanitization methods are selected based on the equipment and sensitivity of information previously processed.
Establishes security and operational requirements for remote work. It addresses endpoint protection, secure connectivity, workspaces, confidentiality, access, and prevention of unauthorized viewing.
Defines how vulnerabilities are identified, assessed, prioritized, tracked, remediated, and verified. The program uses recurring scanning, independent testing, monitoring, and escalations.
Defines how new tools and services are requested, risk-assessed, approved, and recorded before use. Reviews consider intended use, data sensitivity, vendor risk, access requirements, licensing, and compliance exposure.
Establishes a risk-based framework for classifying, assessing, contracting, monitoring, and periodically reviewing vendors. Reviews consider security, privacy, availability, financial stability, hosting, incidents, and independent assurance.
Defines how visitors are registered, authorized, supervised, and restricted at Xano office locations. The policy is designed to reduce unauthorized physical access to systems, workspaces, and sensitive information.
Defines how permitted and restricted applications, services, connections, and resources are managed. These controls support a more controlled operating environment and reduce exposure to unauthorized or malicious activity.