Document
Xano uses risk assessment and vendor management processes to identify, evaluate, and address risks that may affect its systems, operations, customers, or compliance obligations. A significant portion of Xano’s risk assessment activity relates to the use of third-party vendors, particularly where those vendors support critical services or process sensitive information.
Risk assessments are intended to support informed decision-making, appropriate oversight, and consistent treatment of identified risks. The level of review may vary based on factors such as the intended use, data involved, service criticality, hosting model, and potential impact to us or our customers.
We document relevant risks in a structured risk assessment report. Risks are evaluated using separate numerical ratings for impact and likelihood, on a scale from 1 to 10. These ratings are combined to determine an overall risk score and corresponding classification. Each assessment is designed to capture information such as:
Risk treatment options include mitigation, acceptance, transfer, or avoidance, depending on the nature and severity of the risk.
Risks that meet Xano’s high-risk criteria require review and approval by appropriate management before the related system, service, or vendor is approved for use. This process is intended to ensure that elevated risks are understood, documented, and addressed at the appropriate level.
Risk assessments involving sensitive data or as part of our critical infrastructure are reviewed and updated periodically, and may also be reassessed when there are material changes to the service, intended use, data processing activities, threat landscape, or contractual relationship.
Vendor risk assessments build on our general risk methodology and include additional review of the vendor’s security, privacy, operational, legal, and business posture. Depending on the nature of the service, we evaluate areas such as:
The depth of each assessment is based on the vendor’s role, access, criticality, and the sensitivity of data involved.
Vendors that process sensitive data on Xano’s behalf are required to enter into appropriate data protection terms. This includes a Data Processing Addendum or equivalent agreement where possible. These agreements are intended to address relevant privacy, confidentiality, security, subprocessing, and data handling obligations.
Vendor oversight does not end after initial approval. We periodically review higher-risk and sensitive-data vendors to confirm that their risk profile and supporting controls remain appropriate. Reassessment typically considers changes in service scope, data use, hosting location, compliance status, contractual terms, financial condition, reported incidents, or other information that could affect the original risk determination.