Deriv, Generali, and Heimstaden run core operations on Xano, with the rules visible, the changes governed, and the infrastructure operated in their cloud or ours.
Evaluating the architecture, not the pitch? The technical breakdown, stage by stage →
The harness, enumerated: AI skills, test suites, dependencies, auth patterns, approved middleware, agent rules, data residency. Set by your team, inherited by every build.
Release flow: sandbox → immutable artifact → review → promote.
The live system, laid out visually — logic, data, APIs — with the evidence attached: tests passed, policies held, who changed what. Readable by everyone who has to sign off.
Managed, bring-your-own-cloud, or self-hosted; your jurisdiction, your keys. The common journey: start in your cloud, the trust gate, and hand over operations when we've earned it.
Every change moves through the same lifecycle: build on a branch, prove it in staging, preview the exact release, then promote to production. Rollback is one step — redeploy the previous release.
A tenant per client, region, or even a user cohort → own database, own URL, own lifecycle. Release with per-tenant access control, backups, and logs.
ISO 9001, SOC 2 Type 2, SOC 3. Stateless PII handling, request-history off-switch, no training on customer data. Security →
Data in Postgres: exportable, always, assisted at volume. Logic, schema, and tests readable and translatable. Export and perpetual-license commitments available.
When Xano operates it, that means scaling, upgrades, and incident response — under SLA, with someone accountable at any hour. Underneath, Autopilot keeps every cluster right-sized continuously, and proves each change safe before it makes it.
Xano runs production backends today: trading operations at Deriv, core systems at Generali across 30+ countries, and a country's property operations at Heimstaden.