
Hooks for Cursor, Claude Code (IDE and CLI), and VS Code on macOS and Windows. Scan and block on prompts, MCP tool calls, tool responses, and shell commands. LLM model responses are monitor-only

Local studio MCP discovery, inventory, and shadow-MCP detection

Remote HTTP and SSE MCP discovery and inventory.

OpenTelemetry audit trail for Claude Cowork sessions: cost, tokens, tool invocations

Claude Compliance API for Claude Enterprise conversations, files, projects, and activity feed. Same detectors as the rest of Nightfall (PII, PHI, PCI, secrets, source code, custom)

One policy across endpoint, SaaS, and AI agents. SIEM export to Splunk, Panther, Sumo. Deploy via Jamf or Intune