Read Nightfall's State of Agentic Data Security 2026 Report
Learn more

Plans and pricing

Control Data Movement in the Age of Agentic AI.

Schedule Your AI Exposure Assessment
Helping everyone from startups to Fortune 500 enterprises protect their data
Chat with a Nightfall expert
Get a demo

Securing data for the world’s most innovative organizations

Snyk
User Testing
Exabeam
Klaviyo
Kandji
Deepwatch
Aarons
Notable
Telnyx
Genesys
Packages

Choose the solution that fits your DLP needs

Nightfall Complete

AI-powered DLP for your entire organization.

Complete visibility and comprehensive protection across your entire SaaS, AI apps, and endpoints in your organization.
$ per user/year
Includes
All Data Detection & Response features
All Data Exfiltration Prevention features
Dedicated customer success manager
Priority support with 1-hour SLA
Best value - Most popular

Complete + AI Agent Security

AI-powered DLP for your entire organization.

Everything in Nightfall Complete, plus AI Agent Security across endpoints, IDEs, MCP, Claude Cowork, and Claude Enterprise.
Choose your coverage:
Tier 1: $ user/year for up to 3 app
Tier 2: $ user/year for all supported apps
$ per user/year
Includes
All Complete features
Hooks for Cursor, Claude Code (IDE and CLI), and VS Code on macOS and Windows. Scan and block on prompts, MCP tool calls, tool responses, and shell commands. LLM model responses are monitor-only
Local studio MCP discovery, inventory, and shadow-MCP detection
Remote HTTP and SSE MCP discovery and inventory.
OpenTelemetry audit trail for Claude Cowork sessions: cost, tokens, tool invocations
Claude Compliance API for Claude Enterprise conversations, files, projects, and activity feed. Same detectors as the rest of Nightfall (PII, PHI, PCI, secrets, source code, custom)
One policy across endpoint, SaaS, and AI agents. SIEM export to Splunk, Panther, Sumo. Deploy via Jamf or Intune

Optional add-on

Data add-on

Data Discovery and Classification Add-On

Perfect for businesses looking to remove inadvertent sensitive data exposure across SaaS apps.
Data pack tiers:
150 GB
Included
1 TB
$/year
3 TB
$/year
5 TB
$/year
20 TB
$/year

Compare Solutions

Feature
Nightfall Complete
Complete + AI Agent Security
Feature
Remove inadvertent sensitive data exposure across 12+ SaaS apps
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
Revoke data access misconfigurations
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
Email encryption
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
AI-based content classification
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
Prevent Shadow AI
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
Stop data exfiltration from Endpoints and Browsers 
Nightfall Complete
check - yes
2 devices per user
Nightfall Complete
check - yes
2 devices per user
Feature
AI-based data lineage
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Feature
Nyx - Autonomous DLP analyst
Nightfall Complete
check - yes
Nightfall Complete
check - yes
Data Discovery & Classification
check - no
check - yes
check - yes
Feature
Scanning and remediation for Data at Rest
Nightfall Complete
check - yes
150GB included;
$$ Add-on for more data volume
Nightfall Complete
check - yes
150GB included;
$$ Add-on for more data volume
Hooks enforcement on Cursor, Claude Code, and VS Code (prompts, MCP tool calls, tool responses, shell)
check - no
check - yes
Local stdio MCP server discovery and inventory
check - no
check - yes
Remote HTTP and SSE MCP server discovery and inventory
check - no
check - yes
Shadow MCP detection with per-server risk scoring
check - no
check - yes
OpenTelemetry audit trail for Claude Code work
check - no
check - yes
Claude Compliance API monitoring for Claude Enterprise conversations, files, projects, and activity feed
check - no
check - yes
One policy across endpoint, SaaS, and AI agents
check - no
check - yes

Calculate your savings
with agentic DLP

See how much time and money you can save based on benchmarks from existing customers
Configuration
Adjust the parameters based on your current environment
Data violations per month
1000
0
5000
Manual investigation time
15 min
0 min
60 min
DLP analyst hourly cost
$100
$0
$500
Projected Savings
Your potential return on investment with AI-powered DLP
213 hours/month
Estimated Time Saved
$21,250
Monthly Cost Savings
6x ROI
Average Return on Investment
$255,000
Annual Cost Savings
* Calculations assume 85% reduction in manual investigation time through AI-based detection, investigation, and response.

Get started in
3 simple steps

Data Exfiltration Prevention

10 minute setup

Connect your first SaaS app or deploy on endpoint
Data Exfiltration Prevention

Immediate protection

Out-of-the-box policies and pre-trained ML detectors help prevent sensitive data exposure and exfiltration immediately
Data Exfiltration Prevention

Automated remediation

Automate response actions and notify end-users with self-remediation options

Frequently Asked Questions

How much does Nightfall cost?

Nightfall is priced per user, per year, across two packages: Nightfall Complete (AI-powered DLP for SaaS, email, GenAI apps, endpoints, and browsers) and Complete + AI Governance (Complete plus full coverage for AI agents, MCP servers, and AI/MCP Gateway). Final pricing depends on user count and data volume. Contact sales for a tailored quote, or start with a free 7-day proof of value.

What is the difference between Nightfall Complete and Complete + AI Governance?

Nightfall Complete delivers two capabilities. First, Data Detection & Response across 12 API-integrated SaaS apps (Google Drive, Slack, GitHub, Jira, Confluence, Zendesk, Salesforce, Microsoft 365, Notion, ChatGPT Enterprise, and more). Second, Data Exfiltration Prevention via the Nightfall endpoint agent, which covers every SaaS app, desktop app, and AI app your users touch. The endpoint agent is not limited to a supported app list.

Complete + AI Governance adds the full AI agent stack: Cursor, Claude Code, VS Code and other AI harnesses hooks enforcement; local (stdio) and remote (HTTP/SSE) MCP server discovery with shadow-MCP detection; MCP gateway policy enforcement; an OpenTelemetry audit trail for Claude Code; and Claude Compliance API monitoring for Claude Enterprise and more.

Both plans use the same policy engine, pre-trained ML detectors and LLM classifiers with powerful remediation and user coaching capabilities.

What is the difference between API-based SaaS coverage and endpoint coverage?

API-based coverage connects Nightfall directly to 12 supported SaaS apps to detect, classify, and remediate sensitive data at rest and in motion inside those apps. This is where Data Detection & Response happens.

Endpoint coverage deploys the Nightfall agent on managed laptops and desktops and inspects data leaving the device to any destination. Every SaaS app in the browser, every desktop app, every AI tool, every file transfer method. If a user pastes a customer record into an unsanctioned AI tool, uploads source code to a personal cloud drive, or exfiltrates data through a niche SaaS app that no vendor has an API for, the endpoint agent inspects and enforces policy on it. There is support for several exfiltration vectors such as file uploads, clipboard paste, personal vs. corporate session differentiation, USB transfers, print monitoring, git push monitoring, CLI activity and more.

Does Nightfall offer a free trial?

Nightfall offers a free 7-day or limited time proof of value instead of a self-serve trial. During the POV, Nightfall's solution experts connect your real environment, measure detection precision on your own data, and quantify actual exfiltration risk. Nightfall provides a free security assessment report for applicable SaaS apps, AI agents, MCP servers in your environment.

How long does Nightfall take to deploy?

Most teams are protected the same day. Connecting a SaaS app or deploying the endpoint agent to hundreds of users takes about 10 minutes. Nightfall's pre-trained ML detectors start finding sensitive data immediately, with no regex writing, tuning, or rule building required. Endpoint agents deploy fleet-wide via Iru, Jamf, Intune or any of your MDM platforms. Alerts export to Splunk, Panther, Sumo Logic, and any SIEM. MCP tools or APIs allow you to automate triage and response.

How many endpoint devices are included per user?

Each user license includes 2 endpoint devices, for example a work laptop and a second machine. Additional endpoint licenses are available at the same per-endpoint annual rate. You do not have to change plan tiers to expand coverage.

What data types can Nightfall detect?

Nightfall's pre-trained AI detectors identify PII (names, SSNs, addresses, dates of birth as an example), PHI, PCI (credit card numbers as an example), API keys and secrets, passwords and credentials, and source code at 95% detection precision. You can also build custom detectors for data unique to your business, such as internal project code names, customer IDs, or product SKUs. The same detectors run identically across SaaS, email, endpoints, browsers, and AI agent traffic.

How does Nightfall achieve 95% detection precision?

Nightfall trains transformer-based detectors on labeled sensitive-data examples rather than relying on regular expressions or keyword lists. Traditional DLP flags any 16-digit number as a credit card, which produces massive false-positive volume. Nightfall's models weigh context, so a 16-digit number in a phone directory is not treated the same as a 16-digit number in a Stripe response. The result is 95% precision on customer data, as evidenced during the limited period proof of value.

How does Nightfall pricing compare to legacy DLP?

Customers report about 50x lower total cost of ownership than legacy DLP suites like Forcepoint, Symantec, and Proofpoint. Two things drive the gap. Per-user pricing bundles SaaS, endpoint, and AI coverage into one platform instead of separate modules with separate contracts, procurement cycles, and admin consoles. AI-based detection cuts manual alert investigation by about 85%. The largest hidden cost of legacy DLP is analyst time spent on false positives, and 95% precision removes most of it.

How is Nightfall different from Microsoft Purview?

Microsoft Purview is content-blind outside the Microsoft 365 ecosystem. It relies on labels, regex, and pattern matching, and it does not inspect data leaving the endpoint to non-Microsoft destinations. Nightfall inspects content directly with ML detectors, covers non-Microsoft SaaS apps (Slack, Google Drive, GitHub, and more), and enforces policy on the endpoint across every browser, desktop app, and AI tool. Customers who kept Purview for M365 typically add Nightfall for everything Purview cannot see.

How is Nightfall different from Cyberhaven?

Cyberhaven tracks data lineage. It knows where a file came from. It does not always accurately identify what the file contains. In addition to data lineage comparable to Cyberhaven, Nightfall inspects content directly with 95% precision AI detectors, so policy can act on "this document contains 500 SSNs" rather than "this document originated in a folder tagged sensitive." Nightfall focuses on lineage and content, because that is what regulators, auditors, and incident responders care about.

Does Nightfall block data or just detect it?

Nightfall does both. Detection alone produces alert queues. Nightfall enforces policy in real time: block a paste into ChatGPT, block an upload to a personal Google Drive, quarantine a Slack message with a customer record, redact PII before it reaches an AI agent. Enforcement can be tuned per policy, per user group, per data class, and per destination across SaaS apps, AI agents or endpoints. There are multiple remediation options such as redact, delete, revoke permissions, apply labels, quarantine, block, coach users, encrypt, disable download and more as per underlying platform capabilities.

Does Nightfall protect against Shadow AI and unapproved AI tools?

Yes. Nightfall detects and blocks sensitive data before it is pasted or uploaded into ChatGPT, Gemini, Perplexity, or any other unsanctioned AI tool, and can redirect users to an approved AI alternative. Complete + AI Governance extends the same protection to developer AI tools: Cursor, Claude Code, and VS Code, with real-time inspection of prompts, MCP tool calls, and shell commands.

What is MCP security, and does Nightfall support it?

MCP (Model Context Protocol) is the standard AI agents use to connect to external tools, files, and data sources. Every MCP connection is a potential exfiltration path.

Complete + AI Governance delivers end-to-end MCP security:

  • Discovery of every local (stdio) and remote (HTTP/SSE) MCP server across the fleet.
  • Shadow-MCP detection with per-server risk scoring for unsanctioned servers.
  • Policy enforcement on MCP tool calls and responses in real time.
  • MCP gateway coverage: enforce data policy at the gateway layer to govern all MCP and tool call usage in the organization.
  • OpenTelemetry audit trail for Claude Code and Claude Compliance API monitoring for Claude Enterprise.

Nightfall is the only DLP platform with coverage across local, remote, and gateway MCP paths.

What does Nightfall AI Governance actually cover?

Complete + AI Governance covers the full lifecycle of AI agent data risk:

  • AI coding assistants. Cursor, Claude Code, and VS Code, with hooks enforcement on prompts, tool calls, and shell commands.
  • MCP servers. Discovery and policy on local (stdio) and remote (HTTP/SSE) MCP servers, including shadow-MCP detection.
  • MCP gateway. Policy enforcement at the gateway layer for centralized AI agent traffic.
  • Audit trails. OpenTelemetry audit stream for Claude Code activity.
  • Claude Enterprise. Claude Compliance API monitoring for organizations standardized on Anthropic.
  • Shadow AI. Endpoint-based detection and blocking of sensitive data flowing to unsanctioned consumer AI tools like ChatGPT and Gemini.

The same detectors that catch PII in Google Drive catch it in a Claude Code prompt. A consistent policy engine covers all of it.

What does Nightfall integrate with?

Nightfall integrates with Iru, Jamf, Intune or any MDM for endpoint deployment, Okta, Google Directory and Entra ID for identity, Splunk, Panther, Sumo Logic, and any SIEM for alert routing, ServiceNow and Jira for incident workflows, and 12 SaaS apps for API-based detection: Google Drive, Slack, GitHub, Jira, Confluence, Zendesk, Salesforce, Microsoft 365, Notion, ChatGPT Enterprise, and more. The endpoint agent inspects traffic to any SaaS or desktop app whether or not Nightfall has a direct API integration.

What compliance certifications does Nightfall hold?

Nightfall is SOC 2 Type II certified, ISO 27001 certified, HIPAA-ready, and GDPR-compliant. Nightfall's own detectors are used by customers in financial services, healthcare, life sciences, and public sector to meet PCI DSS, HIPAA, GLBA, and state privacy law requirements. Data processed by Nightfall is inspected in-tenant where deployment supports it, and full compliance documentation is available under NDA.

Who is Nightfall built for?

Nightfall is built for security teams at organizations from Series A startups to Fortune 500 enterprises that need to prevent sensitive data exposure across SaaS, endpoint, and AI surfaces without deploying a legacy DLP suite. The typical buyer is a CISO or Director of Security Operations at an organization with 250 to 100,000+ users.

How does the Data Discovery and Classification add-on work?

Every Nightfall plan includes 150 GB of data-at-rest scanning to find and remediate sensitive data already sitting in your SaaS apps. To scan more, add-on packs are available in 1 TB, 3 TB, 5 TB, and 20 TB annual tiers. You can scan historical data in Google Drive, Slack, Confluence, and other connected apps without moving to a new base plan.

Is there a minimum contract or user count?

Nightfall pricing is annual and per-user. Packages scale from small security teams to Fortune 500 fleets. Contact sales to scope a package, confirm user minimums or start with the free 7-day proof of value to validate fit first.
Start with a 7-day proof-of-value

Ready to remove sensitive data exposure and stop data exfiltration?

Start with a 7-day proof-of-value with our solution experts. We'll help you identify your specific data exposure and exfiltration risks and demonstrate exactly how Nightfall can help.
Satisfaction Guarantee
If we don't identify meaningful data risks during your proof-of-value, we'll provide a free security assessment report for your organization.

Schedule a live demo

Tell us a little about yourself and we'll connect you with a Nightfall expert who can share more about the product and answer any questions you have.
Not yet ready for a demo? Read our report:
The 2026 AI Agent Risk & Action Report