SAN FRANCISCO — October 2, 2026 — Nightfall AI, the AI-native data security platform, today announced record commercial and product momentum for September 2026. The company surpassed its previous quarter's record annual recurring revenue in September alone, a full month ahead of plan, closed the largest deal in its history, and added another decacorn from the Forbes AI 50 to its customer base.
The results reflect accelerating enterprise demand for a single control layer over sensitive data movement across both employees and AI agents, as organizations adopt coding assistants, copilots and MCP-connected workflows faster than legacy data loss prevention tools can govern them.
"Data security was built around humans. That world no longer exists," said Rohan Sathe, CEO and co-founder of Nightfall AI. "AI agents now move enterprise data at machine speed, and most security teams have controls for employees but not for agents. September showed that the market understands the difference. Customers are choosing one policy, enforced in real time, across every surface where data moves."
September product highlights
Nightfall for Claude Inference Hooks. Sensitive data is allowed or blocked before Claude reads it. A single integration covers Claude on web, desktop and mobile, Claude Cowork, Claude Code and Claude in Slack, regardless of the device or employee connected. Enforcement happens inside the model call itself, rather than at the network edge.
MCP Gateway. Cursor, Claude Code, VS Code and Claude Cowork now route through one governed proxy. Developers never hold credentials directly. Destructive tools such as delete operations and database drops are removed before an agent can call them. Every MCP server, local or remote, is assigned a risk score and governed under policy.
Expanded data exfiltration controls. The Nightfall endpoint agent now treats scp, curl, wget, rsync, aws s3 and npm as exfiltration paths, and inspects the shell output an agent reads back. AirDrop and Bluetooth transfers can be blocked. AI agents can move data through the same channels as people, and Nightfall now controls both.
Personal file classifiers. Legacy DLP cannot distinguish an employee emailing their own W-2 to an accountant from the exfiltration of customer W-2s. Nightfall's identity-aware classification understands who the employee is and categorizes data movement accordingly, reducing false positives without weakening enforcement.
Global PII coverage: 30 countries, 130 detectors. New national ID and PII detectors for Taiwan, Argentina, Chile and Peru extend Nightfall's content classification coverage, which the company believes to be the broadest in the category.
"We're grateful to our customers for trusting us with the data that matters most, and to a team that is doing some of the best work in AI security anywhere," Sathe added.
About Nightfall AI
Nightfall AI is the AI-native data security platform that gives enterprises real-time control over sensitive data movement across humans and AI agents, MCP servers, SaaS, email and endpoints. Using AI-native detection powered by supervised fine-tuned models, Nightfall enables security teams to secure data flows in minutes, uncover shadow AI and agent chains, and distinguish legitimate business activity from real exfiltration without slowing innovation. Nightfall was co-founded by Rohan Sathe, former founding engineer of Uber Eats, and is backed by Bain Capital Ventures, Venrock, WestBridge Capital, Walden International and Pear VC. Learn more at nightfall.ai.

