Xano TRUST CENTER
Xano
Loading…

Certifications

Document

Security Features

Overview

Paid Xano plans provide security, access management, monitoring, data protection, and deployment features that customers can configure according to their applications, teams, and risk requirements. These capabilities are designed to help customers protect their Xano accounts, control administrative and end-user access, manage sensitive configuration values, review changes, and deploy backend updates more safely.

Feature availability varies by plan, add-on, role, and deployment model. Certain capabilities described below are limited to Pro, Enterprise, Custom, or other eligible plans. Customers should review the linked documentation and their applicable plan details before relying on a feature for a particular security or compliance requirement.

The features described on this page are representative and do not constitute an exhaustive list of all security-related capabilities available within Xano. Additional features, configuration options, implementation guidance, and plan-specific details are available in the Xano Documentation.

Need Help Choosing the Right Security Features?

Organizations evaluating Xano can request a demo with our Sales team to discuss their security, compliance, architecture, and operational requirements in more detail. This helps ensure you are matched with the plan, deployment model, and security capabilities most appropriate for your needs.

For general security-related questions, contact us at security@xano.com.

Account Authentication & Session Security

Individual users can enable two-factor authentication for their Xano accounts, adding an authentication step beyond the account password. Account settings also support an inactivity timeout that automatically signs a user out after a configured period without activity.

Learn more:

Role-Based Access Control

RBAC allows eligible customers to define what team members can view or change within an instance and its workspaces. Custom roles and granular permissions can help organizations limit administrative and development access according to job responsibilities and the principle of least privilege.RBAC availability and permission granularity vary by plan.

Learn more:

Visual Development & Validation

Xano’s visual builder allows customers to inspect, build, test, and refine backend workflows through a visual interface. Backend logic can be viewed either as a node-based Canvas or as a linear Stack, making it easier to understand how each step is configured and how information moves through an endpoint or workflow.

Built-in testing tools allow users to run backend logic and review step-level timing, inputs, outputs, and variables before publishing changes. Information identified as sensitive, such as password fields, is automatically concealed in the run panel. These capabilities can support human review of both manually created and AI-assisted logic by making backend behavior more transparent before deployment. Customers remain responsible for testing and approving their configurations before production use.

Learn more:

Instance Security Policies

The Security Policy panel allows eligible customers to establish security requirements across an instance. Available controls depend on the plan and may include restrictions on direct database queries, inactivity settings, authentication requirements, two-factor authentication enforcement, single sign-on, and network-based access restrictions.

Enterprise security policies may support IP address allowlists and denylists for access to the Xano instance and its APIs. These settings can help organizations apply centralized security standards rather than relying solely on individual user configuration.

Learn more:

Application Authentication & Authorization

Xano provides building blocks that customers can use to implement authentication and authorization within the applications they create. These capabilities include authentication tokens, configurable token expiration, refresh-token workflows, and role-based restrictions for API endpoints. Customers determine how authentication and authorization logic is configured for their own end users. Access checks should be applied to each endpoint, workflow, and data operation according to the application’s security requirements.

Learn more:

Secrets & Environment Variables

Workspace environment variables provide a centralized location for values that need to be reused across APIs, functions, and workflows. They are commonly used for external API keys and other sensitive configuration values that should not be hard-coded into application logic or stored in standard database records. Customers remain responsible for determining which secrets are stored, limiting who can access or change them, and rotating or revoking credentials when appropriate.

Learn more:

Private File Storage

Eligible plans support private file storage for files that should not be publicly accessible through a permanent URL. Private files remain inaccessible until the application generates a time-limited signed URL through backend logic. Customers should intentionally select public or private storage based on the sensitivity of the content and their end-user access requirements.

Learn more:

Backups & Restoration

All paid plans include automatic rolling instance backups, and customers can also create and restore backups manually. Backup options can help you recover from configuration errors, unintended changes, or other events affecting your instance.

Available retention, restoration, and backup-management options may vary by plan or agreement. Customers should also consider whether additional exports or recovery procedures are needed for their own business-continuity requirements.

Learn more:

Branching, Testing, & Controlled Deployment

Branches allow teams to develop and evaluate changes without immediately modifying the live version of a workspace. A branch contains a copy of workspace business logic, such as APIs, functions, add-ons, and tasks, and can be merged when the change is ready for deployment.

Xano also supports unit and workflow testing and CI/CD-style practices that can be combined with branching, triggers, and deployment workflows. These capabilities can help customers separate development from production, validate expected behavior, and reduce risks associated with direct changes to live applications.

Learn more:

AI-Assisted Development Review

Xano Agent can create backend resources such as database tables, APIs, authentication flows, and business logic from customer instructions. Before publishing, users can review generated changes through visual and XanoScript-based views and push the output into a draft state for further inspection. This review process supports human oversight of AI-assisted development. Customers remain responsible for validating generated logic, testing security controls, and approving changes before production deployment.

Learn more:

Audit Logs & Change Visibility

Audit logging capabilities provide searchable information about workspace activity and changes. These records can support collaboration, troubleshooting, internal reviews, and compliance-related oversight by helping teams understand what changed and who performed the activity.

Learn more:

Instance Monitoring & Availability Alerts

The instance dashboard gives administrators visibility into key metrics and information about their Xano environment. Xano also monitors instances and can send instance-down email alerts to administrators when potential downtime is detected. These features support operational awareness but should be considered alongside any application-level logging, monitoring, and alerting the customer requires.

Learn more:

Release Track Preferences

Paid plans allow customers to define when available Xano platform updates are applied to an instance. Release-track options provide greater control over update timing and can give teams time to evaluate changes according to their operational processes. Emergency patches or security-related updates may override the selected preference where necessary. Available release controls vary by plan, with certain advanced or manual update options limited to eligible Enterprise or Custom configurations.

Learn more:

Static Outgoing IP Address

A static outgoing IP address is available on paid plans for requests sent from Xano to external APIs. This can support integrations with third parties that restrict incoming connections through IP allowlisting. The static address applies to outgoing requests and does not itself restrict who may call the customer’s Xano APIs. Note that this feature is currently only available in specific regions; see the link below for eligibility.

Learn more:

Tenant and Environment Isolation

Eligible Enterprise and Custom configurations may provide Tenant Center capabilities for operating isolated copies of a backend, each with its own database, URL, environment variables, backups, and lifecycle. Customers can use these capabilities to separate development, staging, production, customer-specific, or regional environments and manage controlled release deployment between them. Tenant Center permissions can also restrict who may deploy releases, access tenant environments, or manage tenant secrets.

Learn more:

Compliance Center

The Compliance Center provides eligible customers with a centralized history of changes made to workspace objects. It records details such as the affected object, branch, author, date, and type of change, helping teams understand how their backend has evolved and who made specific modifications.

Available reporting includes workspace change history, aggregated administrative activity, and middleware reporting for reviewing whether APIs, functions, and background tasks use expected middleware configurations. These capabilities can support internal audits, change reviews, troubleshooting, team collaboration, and compliance oversight. The Compliance Center does not track changes to individual database records.

Learn more:

100%