Xano TRUST CENTER
Xano
Loading…

Certifications

Document

Policies & Procedures

Overview

Our documented policies, procedures, plans, and other supporting documents form the foundation of Xano’s security program. Together, this documentation establishes expectations for protecting information, managing risk, overseeing personnel and third parties, developing and operating our services, responding to incidents, and continually improving our program.

Policies and procedures are reviewed at least annually and may be updated more frequently to reflect changes in technology, business operations, legal requirements, contractual obligations, identified risks, audit results, and industry practices. Staff are required to review and acknowledge the policies applicable to their roles.

The summaries below provide a high-level overview of our policies and procedures within our security program. This page does not represent an exhaustive list of all of our security program documentation, and is intended to demonstrate the maturity of our program. These summaries intentionally omit confidential configurations, internal system names, control thresholds, testing criteria, and other details to protect that information from misuse.

Policies, Procedures, Plans, and Processes

Acceptable Use of IT Assets Policy

Defines how personnel may use company systems, devices, accounts, applications, cloud services, and AI tools. It prohibits unauthorized activity, credential sharing, circumvention of security safeguards, and handling sensitive information through unapproved methods.

Access Control Policy

Defines how access to Xano-managed systems and information is requested, approved, provisioned, reviewed, modified, and revoked. Access is based on role, business need, least privilege, and appropriate authentication safeguards.

Access Control Process

Operationalizes access-control requirements through documented workflows for granting, reviewing, changing, and removing access. Additional controls apply to privileged or sensitive systems.

API Key Management and Rotation Policy

Establishes requirements for securely storing, using, tracking, rotating, and revoking API keys used in business-critical systems and integrations. It also requires validation of affected services following key changes.

Artificial Intelligence Usage Policy

Governs the secure, ethical, and privacy-conscious use of approved AI tools. Human oversight is required, sensitive-data use is restricted, and AI-generated outputs must be reviewed before they are relied upon or shared externally.

Audit Logging Procedure

Defines how security-relevant activity is logged, reviewed, retained, and escalated across Xano-managed systems. Logging supports accountability, incident response, investigations, and audit evidence.

Backup & Recovery Policy

Defines requirements for backing up and restoring critical systems and information. Recovery capabilities are reviewed and tested periodically to support availability, resilience, and applicable obligations.

Background Check Policy

Establishes pre-employment screening requirements where legally permitted and appropriate to the role. Screening is conducted in accordance with applicable employment, privacy, and fairness requirements.

Bring Your Own Device (BYOD) Policy

Sets security and approval requirements for personally owned devices used to access Xano systems or information. Required safeguards depend on the device, role, systems accessed, and data sensitivity.

Business Continuity Plan

Defines how essential business operations may be sustained or restored following a significant disruption. It addresses critical services, communication, dependencies, recovery priorities, and organizational coordination.

Business Impact Analysis Process

Provides a structured method for identifying critical services, dependencies, and the potential consequences of disruption. Results inform continuity planning, recovery priorities, and resource requirements.

Business Relationship Management Policy

Establishes expectations for managing strategic customer and partner relationships. It addresses service reviews, contractual alignment, formal complaints, performance, and ongoing communication.

Capacity Management Policy

Defines how infrastructure and service capacity are managed. The process considers current usage, expected growth, service changes, and applicable availability requirements.

Change Management System Policy

Establishes a controlled process for documenting, assessing, testing, approving, implementing, and reviewing significant internal changes and changes to Xano offerings. Change records support risk evaluation, traceability, rollback planning, and accountability.

Clear Desk Clear Screen Policy

Requires personnel to secure screens and work areas when unattended and to limit physical or visual exposure of sensitive information. The requirements apply to office and remote work environments.

Communication Security Policy

Defines safeguards for protecting information transmitted through networks, remote-access methods, email, collaboration platforms, and other communication channels. Approved tools and appropriate encryption are required based on sensitivity.

Content Posting Policy

Governs the review and publication of content through official Xano channels. It is designed to protect confidential information, support accuracy, and maintain alignment with legal and organizational requirements.

Continuous Improvement Policy

Defines how audit results, incidents, risk reviews, testing, feedback, and operational observations are used to improve controls and processes. Corrective actions and significant issues are documented, tracked, and reviewed.

Corporate Social Responsibility Policy

Outlines Xano’s approach to ethical business conduct, environmental considerations, workforce practices, privacy, and governance. It provides a framework for responsible organizational decision-making.

Cryptographic Control Policy

Establishes requirements for the appropriate use and management of encryption and related cryptographic safeguards. It addresses data protection in storage, transmission, endpoints, and supported systems.

Customer Complaint Handling Procedure

Defines how customer complaints are received, documented, assessed, investigated, escalated, and resolved. Trends and recurring issues may be further reviewed to identify broader improvements.

Customer Service Standards Policy

Sets expectations for the customer support team or other staff who may access customer environments or data during support activities. It addresses authorized access, appropriate handling, escalation, and professional conduct.

Data Classification Policy

Defines information-classification categories and the handling, access, storage, transmission, and disclosure requirements associated with each level. Controls are applied according to sensitivity and potential impact.

Data Deletion Policies

Establishes requirements for retaining, deleting, anonymizing, and securely disposing of information throughout its lifecycle. Legal, contractual, operational, and privacy obligations are considered when determining retention and deletion.

Data Deletion Procedure

Defines the operational steps for processing account-deletion and verified privacy-related deletion requests. It addresses request validation, system removal, applicable retention exceptions, and secure disposal.

Data Privacy Complaint Handling Procedure

Defines how privacy-related complaints are received, investigated, documented, and resolved. The process includes escalation and corrective action where appropriate.

Data Subject Access, Correction, and Erasure Request Procedure

Supports verified requests involving access, correction, deletion, and other applicable privacy rights. Requests are assessed according to jurisdiction, identity verification, Xano’s processing role, and permitted legal exceptions.

Development Projects Policy

Governs internally sponsored development projects, exploratory work, and public releases associated with Xano. It addresses approval, security, licensing, intellectual property, compliance, and launch readiness.

Device Provisioning Procedure

Defines how company-owned devices are requested, approved, configured, secured, returned, and sanitized. Devices must meet applicable security requirements before accessing sensitive systems.

Disaster Recovery Plan

Defines how critical systems are restored following significant infrastructure or system disruption. Recovery capabilities are tested periodically, and outcomes are reviewed for improvement.

Disciplinary Action Policy

Establishes a fair process for addressing violations of security, privacy, acceptable-use, or workplace requirements. Actions are based on the nature and severity of the issue.

DPF Privacy Complaint Procedure (JAMS)

Defines the process for handling unresolved privacy complaints covered by the Data Privacy Framework through an independent dispute-resolution mechanism. It applies to eligible personal information for which Xano acts as a controller.

Drug-Free Workplace Policy

Sets expectations for maintaining a safe and professional workplace free from unlawful substance use. Requirements are applied in accordance with applicable law and may include additional standards for sensitive roles.

Employee Onboarding & Offboarding Policy

Defines the security, documentation, access provisioning, and training requirements that apply when staff join Xano, as well as the offboarding steps when staff leaves Xano. Access is provisioned based on role and promptly removed following departure.

Employee Transfer Policy

Requires access and responsibilities to be reviewed when personnel change roles. Permissions are adjusted to remain aligned with current duties and least-privilege principles.

Employment Termination Policy

Defines the organizational and security steps associated with voluntary and involuntary separations. It addresses access removal, company intellectual property, documentation, and applicable legal requirements.

Encryption Policy

Defines requirements for protecting sensitive information through encryption at rest and in transit. It also addresses encryption expectations for devices, communications, and approved data-handling methods.

Ethics Policy

Sets expectations for lawful, ethical, and professional conduct. It addresses conflicts of interest, confidentiality, responsible use of company resources, respectful behavior, and reporting concerns to appropriate management.

External Audit Request Procedure

Defines how customer and third-party audit requests are reviewed, approved, scoped, and fulfilled. Evidence is provided through controlled channels in accordance with contractual and confidentiality requirements.

Flow Control Policy

Defines how data and communications are managed across Xano’s critical systems. It addresses network segmentation, permitted flows, filtering, access restrictions, and periodic review.

Government Data Request Policy

Defines how legal and government requests for information are validated, reviewed, documented, and fulfilled. The process is designed to limit disclosure to information appropriately covered by a valid request.

Hiring Process

Defines the steps used to recruit, evaluate, select, screen, and onboard personnel. It includes role-appropriate interviews, required documentation, background screening, training, and controlled access provisioning.

Impersonation Logs Audit Procedure

Defines how authorized customer-account access and impersonation activity is reviewed for legitimacy and appropriate business purpose. Suspicious or unsupported activity is escalated for investigation.

Incident Management & Service Request Process

Defines how operational incidents and service requests are categorized, assigned, tracked, escalated, communicated, and resolved. Security-related events are directed to appropriate response personnel.

Information Security Communication Policy

Defines how security-related information is communicated to internal and external stakeholders. It addresses policy updates, incidents, audits, regulatory matters, and approved communication channels.

Information Security Incident Response Procedure

Defines how security incidents are detected, assessed, contained, investigated, remediated, communicated, and reviewed. The process includes post-incident analysis and corrective actions.

Information Security Objectives and Plan

Documents measurable information-security objectives and the activities used to achieve them. Progress is reviewed through management oversight and adjusted as business and risk priorities change.

Information Security Policy

Establishes the overall framework for protecting the confidentiality, integrity, and availability of information. It provides the foundation for Xano’s security governance, objectives, controls, and continual-improvement activities.

Internal App Deployment Policy

Requires internally developed applications and automations to undergo security and risk review proportionate to their intended use and the information they process. Material changes are also subject to change-management requirements.

Internal Audit Program Procedure

Defines recurring internal audit activities used to evaluate whether controls and processes continue to operate as intended. The program includes sampling, testing, documentation review, evidence validation, and corrective-action follow-up.

Supports the identification, tracking, and management of applicable legal, regulatory, certification, attestation, and contractual obligations. Incorporates relevant requirements into policies, controls, and compliance priorities.

Mobile Device Policy

Defines security requirements for mobile devices used to access Xano systems or information. It addresses authentication, updates, screen protection, notifications, connectivity, and appropriate data handling.

Office Etiquette Policy

Sets expectations for professional conduct, workspace use, security awareness, visitor handling, and information protection at Xano office locations. This policy complements broader physical and workplace-security requirements.

Onboarding Procedure - Access Provisioning

Defines the operational steps for completing required agreements, screening, training, endpoint controls, and role-based access before new personnel begin work. Access is provisioned only after applicable prerequisites are satisfied.

Open Communication & Staff Wellbeing Policy

Encourages personnel to raise concerns relating to work, conduct, workload, or wellbeing through available reporting channels. It supports respectful handling, confidentiality, and non-retaliation.

Operational Security Process

Defines day-to-day requirements for secure system operation. It addresses access, malware prevention, software management, backups, monitoring, maintenance, and controlled administrative activity.

Outbound Marketing Policy

Establishes requirements for lawful and responsible outbound marketing. It addresses permitted outreach, transparency, opt-out handling, suppression practices, and regional privacy requirements.

Defines eligibility, accrual, use, and administration of paid time off and related leave benefits. It supports consistent workforce management and operational planning.

Parental Leave Policy

Defines available parental-leave benefits and related eligibility, administration, and coordination with applicable legal programs. It supports workforce wellbeing and continuity.

Password Management Policy

Establishes requirements for creating, storing, protecting, and managing passwords and other authentication credentials. It also addresses account protection, reuse, sharing, and approved password-management methods.

Patch Management Life Cycle

Defines how software and security updates are identified, prioritized, tested, deployed, verified, and monitored. The process is designed to address known risks while reducing the chance of unintended impact.

Performance Evaluation Policy

Defines how employee performance and competency are reviewed. Evaluations support accountability, development, role alignment, and consistent management decisions.

Phishing Prevention Policy

Defines how personnel are trained to identify, report, and respond to phishing and related social-engineering threats. It also establishes escalation and response expectations following suspected exposure.

Policy Exception Handling Process

Defines how exceptions to established policies are requested, assessed, approved, documented, and reviewed. Exceptions are intended to be controlled, justified, time-bound, and subject to risk oversight.

Privacy and Data Protection Policy

Establishes the principles and requirements governing personal-information processing. It addresses transparency, lawful use, privacy by design, data minimization, individual rights, security, retention, and vendor oversight.

Quality Policy

Defines Xano’s commitment to consistent service delivery, customer requirements, risk-based decision-making, process oversight, and continual improvement. Quality objectives are integrated with security, privacy, and operational obligations.

Record Retention & Protection Policy

Defines how business, security, compliance, privacy, and operational records are retained, protected, archived, and disposed of. Controls apply throughout the record lifecycle.

Reversibility Procedure (Offboarding Enterprise Clients)

Defines how enterprise customers may export data and transition away from Xano services. It addresses customer control, account closure, retention, deletion, and orderly offboarding.

Risk Assessment & Treatment Plan

Defines the methodology used to identify, assess, score, treat, document, and review risks. Treatment options include mitigation, avoidance, transfer, and acceptance, with elevated risks requiring additional oversight from top management.

Risk Management Policy

Establishes the overall framework for managing security, privacy, operational, vendor, compliance, and technology risks. It governs risk ownership, treatment, monitoring, review, and management approval.

Rollback Capability & Back Out Procedure

Defines how system changes may be safely reversed when deployment issues or security events occur. It addresses pre-deployment planning, restoration, authorization, validation, and post-event review.

Secure Software Development Lifecycle (SSDLC)

Integrates security, privacy, quality, and compliance considerations throughout planning, design, development, review, testing, release, and post-deployment activities. AI-assisted outputs remain subject to human review and standard development controls.

Security Impact Analysis Process

Provides a structured method for evaluating the potential impact of security risks on systems, information, operations, finances, and compliance obligations. Results inform risk treatment and security priorities.

Sexual Harassment Prevention Policy

Prohibits sexual harassment and related inappropriate conduct. It provides reporting channels, investigation expectations, confidentiality protections, and non-retaliation safeguards.

Software Program Usage Policy

Requires software to be evaluated, approved, licensed, and used within its authorized scope. Unauthorized installation, use, or removal is restricted.

Staff Support Response Procedure

Provides managers with guidance for responding when personnel raise concerns relating to stress, workload, wellbeing, or workplace conditions. It addresses listening, practical support, escalation, documentation, and follow-up.

Subcontracting Procedure

Defines how subcontractors are evaluated, approved, contracted, monitored, and reviewed. Requirements are proportionate to the services performed, associated risks, and information or systems involved.

Supplier Management Policy

Defines how third-party suppliers are evaluated and overseen throughout the relationship lifecycle. Reviews consider service criticality, security, privacy, contractual obligations, performance, and data-processing activities.

System Maintenance Policy

Defines requirements for authorized, documented, and controlled maintenance of systems, applications, infrastructure, and devices. Maintenance activities are planned and verified to reduce security and availability risks.

Technology Equipment Disposal or Reuse Policy

Defines how devices and storage media are securely wiped, reused, recycled, or destroyed. Sanitization methods are selected based on the equipment and sensitivity of information previously processed.

Teleworking Policy

Establishes security and operational requirements for remote work. It addresses endpoint protection, secure connectivity, workspaces, confidentiality, access, and prevention of unauthorized viewing.

Threat & Vulnerability Management Policy

Defines how vulnerabilities are identified, assessed, prioritized, tracked, remediated, and verified. The program uses recurring scanning, independent testing, monitoring, and escalations.

Tool Request Policy

Defines how new tools and services are requested, risk-assessed, approved, and recorded before use. Reviews consider intended use, data sensitivity, vendor risk, access requirements, licensing, and compliance exposure.

Vendor Risk Management Policy

Establishes a risk-based framework for classifying, assessing, contracting, monitoring, and periodically reviewing vendors. Reviews consider security, privacy, availability, financial stability, hosting, incidents, and independent assurance.

Visitor Control Policy

Defines how visitors are registered, authorized, supervised, and restricted at Xano office locations. The policy is designed to reduce unauthorized physical access to systems, workspaces, and sensitive information.

Whitelisting/Blacklisting Policy

Defines how permitted and restricted applications, services, connections, and resources are managed. These controls support a more controlled operating environment and reduce exposure to unauthorized or malicious activity.

100%