

.webp)

Nightfall is priced per user, per year, across two packages: Nightfall Complete (AI-powered DLP for SaaS, email, GenAI apps, endpoints, and browsers) and Complete + AI Governance (Complete plus full coverage for AI agents, MCP servers, and AI/MCP Gateway). Final pricing depends on user count and data volume. Contact sales for a tailored quote, or start with a free 7-day proof of value.
Nightfall Complete delivers two capabilities. First, Data Detection & Response across 12 API-integrated SaaS apps (Google Drive, Slack, GitHub, Jira, Confluence, Zendesk, Salesforce, Microsoft 365, Notion, ChatGPT Enterprise, and more). Second, Data Exfiltration Prevention via the Nightfall endpoint agent, which covers every SaaS app, desktop app, and AI app your users touch. The endpoint agent is not limited to a supported app list.
Complete + AI Governance adds the full AI agent stack: Cursor, Claude Code, VS Code and other AI harnesses hooks enforcement; local (stdio) and remote (HTTP/SSE) MCP server discovery with shadow-MCP detection; MCP gateway policy enforcement; an OpenTelemetry audit trail for Claude Code; and Claude Compliance API monitoring for Claude Enterprise and more.
Both plans use the same policy engine, pre-trained ML detectors and LLM classifiers with powerful remediation and user coaching capabilities.
API-based coverage connects Nightfall directly to 12 supported SaaS apps to detect, classify, and remediate sensitive data at rest and in motion inside those apps. This is where Data Detection & Response happens.
Endpoint coverage deploys the Nightfall agent on managed laptops and desktops and inspects data leaving the device to any destination. Every SaaS app in the browser, every desktop app, every AI tool, every file transfer method. If a user pastes a customer record into an unsanctioned AI tool, uploads source code to a personal cloud drive, or exfiltrates data through a niche SaaS app that no vendor has an API for, the endpoint agent inspects and enforces policy on it. There is support for several exfiltration vectors such as file uploads, clipboard paste, personal vs. corporate session differentiation, USB transfers, print monitoring, git push monitoring, CLI activity and more.
MCP (Model Context Protocol) is the standard AI agents use to connect to external tools, files, and data sources. Every MCP connection is a potential exfiltration path.
Complete + AI Governance delivers end-to-end MCP security:
Nightfall is the only DLP platform with coverage across local, remote, and gateway MCP paths.
Complete + AI Governance covers the full lifecycle of AI agent data risk:
The same detectors that catch PII in Google Drive catch it in a Claude Code prompt. A consistent policy engine covers all of it.

