Xano TRUST CENTER
Xano
Loading…

Certifications

Document

Risk & Vendor Management

Overview

Xano uses risk assessment and vendor management processes to identify, evaluate, and address risks that may affect its systems, operations, customers, or compliance obligations. A significant portion of Xano’s risk assessment activity relates to the use of third-party vendors, particularly where those vendors support critical services or process sensitive information.

Risk assessments are intended to support informed decision-making, appropriate oversight, and consistent treatment of identified risks. The level of review may vary based on factors such as the intended use, data involved, service criticality, hosting model, and potential impact to us or our customers.

Risk Methodology

We document relevant risks in a structured risk assessment report. Risks are evaluated using separate numerical ratings for impact and likelihood, on a scale from 1 to 10. These ratings are combined to determine an overall risk score and corresponding classification. Each assessment is designed to capture information such as:

  • The intended use of the system, service, or vendor
  • Relevant threat and vulnerability categories
  • Identified threat sources
  • The selected risk treatment decision
  • Applicable risk treatment controls
  • Residual risk ratings following treatment
  • The overall risk classification

Risk treatment options include mitigation, acceptance, transfer, or avoidance, depending on the nature and severity of the risk.

Risk Approval & Review

Risks that meet Xano’s high-risk criteria require review and approval by appropriate management before the related system, service, or vendor is approved for use. This process is intended to ensure that elevated risks are understood, documented, and addressed at the appropriate level.

Risk assessments involving sensitive data or as part of our critical infrastructure are reviewed and updated periodically, and may also be reassessed when there are material changes to the service, intended use, data processing activities, threat landscape, or contractual relationship.

Third-Party Vendor Assessment

Vendor risk assessments build on our general risk methodology and include additional review of the vendor’s security, privacy, operational, legal, and business posture. Depending on the nature of the service, we evaluate areas such as:

  • Security and privacy practices
  • Financial stability
  • Availability history and service-level commitments
  • Independent audits, certifications, or attestations
  • Contractual protections and data processing terms
  • Known security incidents, litigation, or regulatory concerns
  • Customer feedback and market reputation
  • Data hosting and processing locations

The depth of each assessment is based on the vendor’s role, access, criticality, and the sensitivity of data involved.

Data Processing Agreements With Our Vendors

Vendors that process sensitive data on Xano’s behalf are required to enter into appropriate data protection terms. This includes a Data Processing Addendum or equivalent agreement where possible. These agreements are intended to address relevant privacy, confidentiality, security, subprocessing, and data handling obligations.

Ongoing Vendor Oversight

Vendor oversight does not end after initial approval. We periodically review higher-risk and sensitive-data vendors to confirm that their risk profile and supporting controls remain appropriate. Reassessment typically considers changes in service scope, data use, hosting location, compliance status, contractual terms, financial condition, reported incidents, or other information that could affect the original risk determination.

100%