nightlyx

Security at NightlyX

Your pipeline runs through us — leads, conversations, and connected tools. Here is exactly how that data is protected. Everything on this page is true today, not aspirational.

Data protection

  • All traffic is encrypted in transit with TLS 1.2+.
  • Data is encrypted at rest (AES-256) in our database provider.
  • Integration credentials (API keys you connect) are additionally encrypted at the application layer with AES-256-GCM before storage — a database read alone cannot reveal them.
  • Payments are processed entirely by Stripe (PCI-DSS Level 1). Card numbers never touch NightlyX servers.

Isolation & access

  • Every workspace is isolated with database-enforced row-level security — queries are scoped to your workspace at the database layer, not just in application code.
  • Production access is restricted to the founding team with MFA.
  • LinkedIn connection uses hosted authentication — NightlyX never sees or stores your LinkedIn password.

Your rights (GDPR)

  • Export everything: a self-serve endpoint returns your workspace data in machine-readable form.
  • Delete everything: account deletion permanently removes your workspace, leads, messages, and credentials.
  • We contact prospects only on your instruction, and unsubscribes are honored permanently at the database level.

Operations

  • Automated daily security review of code changes, dependencies, and live endpoints.
  • Error monitoring with alerting on production incidents.
  • AI spend and outreach volume are capped per workspace with fail-closed limits — a malfunction stops sending rather than over-sending.
  • All outreach respects platform-safe daily limits paced by your connected sending tools.

Subprocessors

We build on infrastructure providers that hold their own independent certifications:

SupabaseDatabase & authentication (SOC 2 Type II)
VercelApplication hosting (SOC 2 Type II, ISO 27001)
StripePayments (PCI-DSS Level 1)
OpenAI & AnthropicAI text generation (SOC 2 Type II)
ResendTransactional email (SOC 2 Type II)
UnipileLinkedIn account connection

Compliance roadmap

NightlyX is an early-stage product built security-first on certified infrastructure. A formal SOC 2 examination is on our near-term roadmap; we'll publish the report here when the audit completes. We do not claim certifications we have not earned — if a compliance document (DPA, security questionnaire) would unblock your team, email us and we'll turn it around fast.

Reporting a vulnerability

Found something? Email josh@nightlyx.co with details. We respond within 24 hours and won't pursue good-faith researchers.