Document
Xano’s security program is supported by qualified personnel, ongoing training, organization policies and procedures, and endpoint protections designed to reduce risks associated with human error, credential misuse, phishing, malware, and unauthorized access. These controls begin before employment and continue throughout each staff member’s time with Xano.
Before hire, candidates are evaluated to confirm that their experience and qualifications are appropriate for the responsibilities and seniority of the role. This evaluation generally includes review of the candidate’s professional background and a structured interview process.
As part of onboarding, personnel are required to sign our Non-Disclosure Agreement (NDA), Intellectual Property (IP) Agreement, and all other applicable legal documentation. New hires are also subject to background screening where permitted by applicable law and appropriate to the role.
New staff members must complete security, privacy, and workplace training as part of the onboarding process. Required training includes general cybersecurity awareness and may also cover topics such as protection of protected health information, GDPR awareness, ISO 27001 awareness, and harassment prevention.
Training requirements are designed to help personnel understand their responsibilities for protecting Xano systems, customer data, confidential information, and workplace resources.
Xano assigns short monthly training modules to reinforce common cybersecurity concepts and address relevant or emerging risks. Topics may include phishing, credential security, social engineering, artificial intelligence threats, data handling, remote work security, malware, and other risks relevant to our security program.
Staff must also complete annual training campaigns to refresh and validate their understanding of key security, privacy, compliance, and workplace requirements.
Staff are included in phishing simulation exercises designed to strengthen awareness of social engineering and email-based threats. These exercises help us assess the effectiveness of our awareness program, identify areas where additional education may be useful, and reinforce appropriate reporting practices.
Simulation results are used for training and program improvement. Specific testing methods, schedules, and results are not published publicly.
All staff members are required to review and acknowledge Xano’s employee handbook and policy manual annually. These materials describe applicable security, privacy, acceptable use, confidentiality, workplace, and compliance expectations.
Employees and consultants who access sensitive data and systems must use devices that meet applicable endpoint security requirements. As part of onboarding, relevant personnel are required to install an approved endpoint detection and response sensor before receiving access to sensitive data and systems.
Endpoint protection is designed to help detect, block, and respond to threats such as malware, suspicious activity, credential attacks, and other common endpoint risks. Xano also applies endpoint security requirements intended to support appropriate device configuration, monitoring, and incident response. Specific endpoint tools, detection logic, alert thresholds, and response procedures are not published publicly because they form part of Xano’s internal security operations. Limiting disclosure helps preserve the effectiveness of these controls and reduces the risk of attempted evasion.