Document
The security of data and the compliance of applications or projects built within Xano rely on the shared responsibility model. Xano provides the backend platform, managed services, infrastructure (excluding custom deployments), security controls, compliance program, and supporting documentation described throughout this Trust Center. However, Xano cannot take full responsibility for the security or compliance of applications, APIs, workflows, databases, integrations, AI-assisted outputs, or business logic that customers design, configure, deploy, and operate within their own Xano accounts.
Many customers may be subject to their own legal, regulatory, or contractual compliance requirements, particularly when working with regulated or special categories of data such as protected health information (PHI), financial data, education records, controlled unclassified information (CUI), or government data. This page does not constitute legal or compliance advice, and users working with sensitive data are advised to consult an expert to understand their specific requirements.
The shared responsibility model means that Xano is responsible for securing and operating the Xano platform/services, while customers are responsible for how they use the platform and deploy the applications they create.
This page applies generally across Xano paid plans unless otherwise specified. However, specific responsibilities, features, commitments, support options, service levels, deployment models, and contractual obligations may vary by plan or agreement. Enterprise or Custom plans may include additional or different shared responsibilities, especially for custom deployments, self-hosted or dedicated cloud configurations, implementation support, or other customer-specific arrangements, as defined in the enterprise Master Services Agreement or similar contractual agreements.
The goal of this page is to provide an overview of some responsibilities that customers bear when using Xano to maintain security best practices, and it is not intended to be exhaustive.
Xano’s Responsibilities: Xano provides platform features that enable customers to manage workspace users, roles, permissions, and authentication and authorization settings. Available features vary by plan. Xano also maintains platform-level access control safeguards for Xano-managed systems and services and limits staff access to customer environments to authorized business needs, as described in our Access Control Policy.
Customer’s Responsibilities: Customers are responsible for configuring workspace access, roles, permissions, and authentication appropriately; regularly reviewing and updating user access; managing access to third-party applications, integrations, APIs, and data; and implementing appropriate end-user access controls within applications built on Xano.
Xano’s Responsibilities: Xano provides platform capabilities that support application development, deployment, operations, API management, workflows, database logic, and related functions. Capabilities vary by plan. Xano also provides security and compliance documentation to help customers evaluate platform-level controls.
Customer’s Responsibilities: Customers are responsible for designing, configuring, testing, and approving applications, APIs, workflows, and business logic before production use. Customers must implement appropriate authentication, authorization, validation, and secure data flows, and ensure that applications built on Xano meet applicable security, privacy, regulatory, and business requirements.
Xano’s Responsibilities: Xano provides platform capabilities for storing, processing, managing, and exporting customer data, with features varying by plan. We apply platform-level safeguards designed to protect customer data processed through Xano and provide supporting documentation regarding our data protection and privacy practices.
Customer’s Responsibilities: Customers are responsible for determining what data is placed into Xano and whether that data is sensitive, regulated, or subject to specific requirements. Customers must maintain the accuracy, integrity, retention, deletion, and lawful use of customer-controlled data and use appropriate plans, configurations, and contractual terms before processing regulated data.
Xano’s Responsibilities: For Xano-managed plans, Xano provides backup schedules, retention periods, and restoration capabilities, which vary by plan and agreement. Xano also maintains platform-level continuity and recovery practices for Xano-managed services.
Customer’s Responsibilities: Customers are responsible for understanding the backup, export, retention, and recovery capabilities available under their plan or agreement. For self-hosted plans, customers must configure, manage, test, and recover backups in accordance with their Xano contract and their internal requirements. Customers are also responsible for maintaining any additional backups, exports, or restoration procedures required by their own policies or obligations and for developing business continuity and disaster recovery plans, including defining RTO and RPO objectives for their own applications and operations.
Xano’s Responsibilities: Xano provides AI-assisted development and validation features, as well as agents governed by Xano’s AI Terms. Xano also provides visibility into generated or modified backend components, allowing customers to review logic before use.
Customer’s Responsibilities: Customers are responsible for reviewing, validating, testing, and approving AI-generated or AI-assisted outputs before production use. Customers must ensure that AI-assisted configurations, logic, workflows, and data flows meet their security and compliance requirements, and that they treat AI-assisted features as support tools rather than substitutes for secure development, human review, testing, or change control. If customers connect customer-managed AI models, LLMs, or third-party AI services to Xano, they are fully responsible for the security, compliance, and proper configuration of those integrations and systems.
Xano’s Responsibilities: Xano offers deployment options based on the applicable plan, including Xano-managed hosting on Google Cloud Platform (GCP) and Custom or self-hosted deployment options where Xano is deployed within customer-controlled infrastructure. Xano provides available hosting-region options for Xano-managed deployments. For Xano-managed paid accounts, Xano provides the underlying GCP infrastructure and provisions dedicated resources for each paid account. Xano maintains and secures Xano-managed infrastructure and platform components. Responsibilities for Custom deployments may vary based on the applicable agreement.
Customer’s Responsibilities: Customers are responsible for selecting the deployment model and hosting region appropriate for their security, compliance, data residency, regulatory, and business requirements. For Custom or self-hosted deployments, customers provide and maintain customer-controlled infrastructure and associated cloud configuration, security, networking, and operational controls within the scope of responsibilities defined by the applicable agreement. Customers should also review applicable plan capabilities, deployment options, and contractual requirements before processing regulated or regionally restricted data.
Xano’s Responsibilities: Xano provides backend services, APIs, authentication and authorization features, and platform capabilities that customers can connect to frontend applications. Xano maintains the platform components that support customer-built applications and provides documentation to help customers understand the available backend and security features and how to set up frontend applications.
Customer’s Responsibilities: Customers are responsible for connecting and securing frontend applications, websites, portals, mobile apps, forms, and client-side code that connect to Xano. Customers must implement appropriate end-user authentication, authorization, session handling, privacy notices, consent flows, and input validation, and ensure frontend and backend implementations work together securely and meet applicable requirements.
Xano’s Responsibilities: Xano maintains network security controls for Xano-managed platform services and provides platform features that support secure connections, API usage, and integrations, with features varying by plan. Xano also applies platform-level safeguards for Xano-managed infrastructure and services and conducts routine network security tests.
Customer’s Responsibilities: Customers are responsible for securely configuring customer-managed integrations, API connections, webhooks, domains, client applications, and third-party services. Customers must protect, rotate, and revoke API keys, tokens, secrets, credentials, and other integration materials as needed, and ensure that connected systems and integrations are configured in accordance with their security requirements.
Xano’s Responsibilities: Xano provides logging, visibility, and audit-related capabilities, with features and retention varying by plan. Xano maintains platform-level monitoring and security oversight for Xano-managed services, ensures that customer data access is regularly audited, and provides Trust Center materials that describe Xano’s monitoring and auditability approach.
Customer’s Responsibilities: Customers are responsible for determining what application-level monitoring, alerting, logging, audit trails, and detective controls are required. Customers must implement additional monitoring, custom audit trails, SIEM integrations, alerting, or compensating controls as needed, and review available activity logs in accordance with their security, compliance, and operational needs.
Xano’s Responsibilities: Xano provides security, privacy, compliance, and governance materials to help customers assess the Xano platform. Xano makes applicable contractual documents, add-ons, and regulatory support materials available where appropriate, although some materials require specific plans or upgrades. Xano also maintains its own security and compliance program as described in this Trust Center and applicable agreements.
Customer’s Responsibilities: Customers are responsible for determining which laws, regulations, contracts, policies, and industry requirements apply to their use of Xano. Customers must select appropriate plans, add-ons, configurations, contractual terms, and hosting locations before processing regulated or sensitive data; ensure that their applications, notices, consents, workflows, and processing activities meet applicable obligations; and maintain a security program in accordance with applicable requirements.
Xano’s Responsibilities: Xano provides channels for customers to report suspected security incidents or security concerns, primarily through security@xano.com. Xano reviews, responds to, triages, and resolves reported security events involving Xano services in accordance with Xano’s incident response practices, and communicates with affected customers as required by applicable agreements or legal obligations.
Customer’s Responsibilities: Customers are responsible for promptly notifying Xano of actual or suspected incidents affecting their Xano account, workspace, credentials, integrations, or use of the services. Customers must investigate and address customer-controlled issues such as compromised accounts, exposed credentials, or insecure integrations and cooperate with Xano as needed to assess, contain, or remediate security events involving their use of the platform.