Nightfall sees record September and signs largest deal in company history
Learn more

September 2026 Product Updates

On this page

September was the month Nightfall's control layer reached inside the model call. Five releases shipped: Claude Inference Hooks, MCP Gateway, expanded endpoint exfiltration controls, personal file classifiers, and PII coverage across 30 countries. Together they close the gap between what security teams can control when a person moves data and what they can control when an AI agent does.

For years, data security assumed a human was moving the data, through a known channel, with intent you could guess at. That assumption no longer holds. Copilots, coding assistants and MCP-connected agents move sensitive data at machine speed, often with no person in the loop. Every release below applies the same policy to both actors, enforced before data leaves.

Nightfall for Claude Inference Hooks

Sensitive data is now allowed or blocked before Claude reads it. Inference Hooks put Nightfall's detection engine inside the model call itself, so enforcement happens at the point where data meets the model, not at a network proxy that only sees traffic crossing a boundary.

One integration, every Claude surface. A single connection covers Claude on web, desktop and mobile, Claude Cowork, Claude Code and Claude in Slack. It works regardless of which device the employee is on or whether that device runs the Nightfall endpoint agent. A contractor on an unmanaged laptop and an engineer on a corporate Mac are governed by the same policy.

What gets inspected. Every prompt a user sends, every tool call Claude makes, and every tool response that comes back is classified in real time against Nightfall's detectors for PII, PHI, PCI, secrets, source code and corporate IP. If the content violates policy, the call is blocked before the model processes it and the user sees a coaching message explaining why. Model responses are also monitored, so sensitive content Claude generates is flagged and logged for the security team.

Why it matters. Until now, controlling what goes into a hosted AI assistant meant choosing between a browser plugin (which misses desktop and mobile), a network gateway (which misses local sessions and can't read encrypted traffic) or an endpoint agent (which misses unmanaged devices). Inference Hooks remove the trade-off: the control point lives where the data is actually read.

Works with the Claude Compliance API. For Claude Enterprise customers, Nightfall also scans chats and files across the organization through Anthropic's Compliance API, raises policy incidents and notifies users. Inference Hooks add real-time blocking on top of that visibility.

MCP Gateway

Every developer AI tool now routes through one governed proxy. Cursor, Claude Code, VS Code and Claude Cowork connect to the MCP Gateway with a single line in their MCP configuration, and from that point every tool call an agent makes passes through policy before it reaches the real MCP server.

Developers never hold the keys. Credentials for downstream MCP servers are brokered by the gateway and encrypted per tenant with AWS KMS. A developer authenticates once through SSO; the gateway injects the right credential for each approved server. No API keys in config files, no tokens in plaintext, nothing to leak when a laptop walks out the door.

Destructive tools are removed before an agent can call them. The gateway prunes dangerous capabilities from a server's tool list at connection time. Operations such as delete_*, database drops, and bulk writes are stripped from what the agent can see, so a prompt injection or a confused model can't trigger them. What remains is governed by role: engineering gets code tools, sales gets CRM, finance gets read-only.

Every MCP server gets a risk score. Local stdio servers and remote HTTP servers alike are discovered automatically, scored on the sensitivity of the systems they touch and the tools they expose, and governed under policy. Approve the handful you need; everything else is blocked by default, with an exception workflow for developers who need access with justification.

Content inspection in flight. Sensitive data returned by a tool call is classified before the agent sees it. Sends to destinations outside policy are blocked. Full lineage is retained for investigation, with zero prompt or response retention by the gateway itself.

Why it matters. Gateway-only products see hosted MCP servers and nothing else; endpoint-only products miss cloud sessions like Cowork. The MCP Gateway sits in the path for both, and it's the same policy engine that governs the human side of the house.

Expanded data exfiltration controls

The Nightfall endpoint agent now controls the channels AI agents use to move data, not just the ones people use. On macOS and Windows, the agent treats command-line transfers and wireless transfers as exfiltration paths, inspects the content, and blocks or coaches according to policy.

Command-line transfer protection. scp, curl, wget, rsync, aws s3 and npm are now monitored as data egress. When a coding agent in Claude Code or Cursor runs a shell command that pushes a file to an external host, a bucket or a package registry, the agent inspects what's being sent before it leaves. This closes the path that network DLP and browser plugins never see: a terminal.

Shell output inspection. Agents don't only send data; they read it. The endpoint agent now scans the shell output an AI agent reads back, so a command that dumps credentials, customer records or source into the agent's context is caught at the same point a human paste would be.

AirDrop and Bluetooth. File transfers over AirDrop (macOS) and Bluetooth (macOS and Windows) can be blocked by policy. Existing MDM Profile v3 deployments get this with no new end-user prompts.

Why it matters. AI agents can exfiltrate data through the same channels people can, and often faster. A policy that stops a person from uploading a customer list to a personal Drive should also stop an agent from curl-ing it to an unknown endpoint. Now it does, from one rule.

Personal file classifiers

Nightfall now tells the difference between an employee handling their own personal documents and an employee moving someone else's. Legacy DLP can't. To a regex engine, a W-2 is a W-2: the one an employee emails to their accountant in March looks identical to a batch of customer W-2s leaving through the same channel. The result is either a flood of false positives or a policy quietly switched off.

How it works. Personal file classifiers combine content detection with identity. Nightfall knows who the employee is, pulls identity from your IdP, and recognizes when a document belongs to that person: their own tax form, pay stub, offer letter, medical bill or ID. Those files are classified as personal and handled under a separate policy from corporate sensitive data.

What changes for the security team. Fewer alerts to triage, because a developer forwarding their own 1099 no longer trips the same rule as a customer data leak. No weaker enforcement, because the corporate W-2 batch is still blocked. Policies can treat the two cases differently: allow personal, block corporate, or coach on both.

Why it matters. The number-one reason DLP gets turned off is noise, and the number-one source of noise is sensitive-looking data that isn't actually a risk. Identity-aware classification removes that category of false positive without asking the security team to write a single exception.

Global PII coverage: 30 countries, 130 detectors

Nightfall now ships 130 pre-trained detectors covering national identifiers across 30 countries. September added Taiwan, Argentina, Chile and Peru, with detectors for national ID numbers, tax IDs, driver's licenses and passports in each.

Why country-specific detectors matter. A US Social Security number and a Chilean RUT don't share a format, a checksum or a context. Generic "ID number" patterns either miss them or match everything that looks like digits. Nightfall's detectors are trained per country and per document type, so a Taiwanese national ID in a Slack message is classified with the same confidence as a US SSN, and the policy that governs it applies worldwide.

Who this is for. Companies operating across Latin America and APAC, fintechs onboarding customers in multiple jurisdictions, and any team that needs one policy to hold up under GDPR, LGPD, PDPA and local data residency rules at once.

Alongside the detectors. The same release cut P95 latency on PHI inspection by 41% across names, addresses, medications and conditions, and shipped an enhanced API key model for secrets detection. Coverage grew and the engine got faster at the same time.

We believe this is the broadest content classification coverage in the category, and we publish the full detector list so you can check.

One policy, every way data moves

Taken together, September's releases mean a single Nightfall policy now enforces at three points for AI agents (inside the model call, at the MCP gateway, on the endpoint) and across every channel people use (endpoint, SaaS, email). Same detectors, same rule, same block, whether a person pastes a customer record into ChatGPT or a Claude agent pulls it through an MCP server and tries to scp it somewhere.

All five releases are generally available to Nightfall customers today. Existing customers can enable Inference Hooks and MCP Gateway from the console or through their CSM; endpoint controls ship with macOS agent 1.2.15 and Windows agent 1.4.39.

If you're evaluating how to govern AI agents alongside the people who use them, book a demo and we'll show you what's leaving today.

AI moves your data. Nightfall controls it.

‍

Schedule a live demo

Tell us a little about yourself and we'll connect you with a Nightfall expert who can share more about the product and answer any questions you have.
Not yet ready for a demo? Read our report:
‍The 2026 AI Agent Risk & Action Report