Document
Xano operates an internal audit program designed to evaluate the continued effectiveness of our security, privacy, compliance, and operational controls. Our program includes monthly, quarterly, semiannual, and annual activities derived from applicable regulatory, contractual, security, compliance, and internal governance requirements.
Internal audit activities may include control sampling, documentation reviews and updates, security awareness activities, technical and operational testing, evidence validation, and follow-up on previously identified issues. The scope and frequency of each activity are based on the control being evaluated, the associated risk, and the requirements of the applicable framework or agreement.
Results from the internal audit program are summarized through Xano’s management review process. These reviews help management evaluate outstanding issues, identify opportunities for improvement, monitor corrective actions, and keep relevant leaders informed about the performance of Xano’s security and compliance programs.
Internal audits are intended to provide ongoing assurance rather than a one-time assessment. Findings, observations, and improvement opportunities are documented and tracked according to their priority and applicable requirements.
The results of internal audits, independent assessments, security testing, incidents, risk reviews, and management feedback are used to inform improvements to Xano’s policies, controls, documentation, training, and technical safeguards. Specific audit schedules, test procedures, samples, findings, and remediation details are not published publicly because they form part of Xano’s internal security and assurance program. Limiting disclosure helps preserve the effectiveness of these controls and reduces the risk of misuse or attempted evasion.
Xano engages Clone Systems, an independent third-party security provider, to conduct an annual penetration test. The assessment includes an OWASP-focused web application test covering designated Xano-operated services, including:
The penetration test is intended to identify potential weaknesses in externally accessible applications and evaluate relevant security controls from an independent perspective. Results are reviewed internally, and identified issues are evaluated and addressed through Xano’s vulnerability management and risk processes.
Our latest penetration test results are available for request below.
Clone Systems also performs quarterly external network vulnerability scans for Xano as an Approved Scanning Vendor, or ASV. These scans assess designated externally accessible components against the applicable ASV scanning requirements and provide independent validation of the scan results.
ASV scan results are reviewed as part of Xano’s vulnerability management program. These scans provide independent validation of applicable external vulnerability scanning requirements, but they do not by themselves represent Xano’s overall PCI DSS compliance status.
Our latest network scan results are available for request below.
Xano conducts an annual disaster recovery test to evaluate its ability to restore critical services following a significant infrastructure disruption. The exercise simulates the loss of production database and compute infrastructure, including the Kubernetes environment, and is intended to validate recovery capability within established recovery parameters.
The annual exercise is designed to:
To protect Xano’s security and resilience posture, detailed scenarios, infrastructure configurations, recovery procedures, timing data, and test artifacts are not published publicly. The frequency and operation of disaster recovery testing are evaluated through applicable independent audits, including our SOC 2 Type 2, ISO 27001, and ISO 27701 audit programs. These assessments provide assurance that recovery testing is performed and governed in accordance with the relevant control requirements.