security

You're handing us read access to production telemetry.

That deserves specifics rather than badges. Here is exactly how the boundaries are drawn and what the AI is and isn't allowed to do.

Tenant isolation
Every database query is scoped to a tenant at the data layer, not by convention in application code. Row-level scoping is applied where the query is built, so a missing filter isn't a bug waiting to leak data across customers — it isn't expressible. Investigations, alerts, runbooks and credentials all inherit the same boundary.
Credentials
Connector credentials are envelope-encrypted with AES-256-GCM: each secret is sealed with its own data key, and that key is itself encrypted. The key material is never stored in the database alongside the ciphertext. Credentials are verified when you connect, so a bad key surfaces at setup rather than mid-incident.
Webhook authenticity
Alert webhooks are authenticated before anything is parsed — HMAC signatures or rotating per-tenant tokens, depending on what your alerting layer can send. Unverified payloads are rejected, not investigated. Tokens can be rotated without redeploying your alerting configuration in place.
Query safety
The model never writes a raw query string against your systems. It composes typed, validated query intents — a bounded structure with a metric, a window, a grouping and filters — which the connector renders into whatever query language the backend speaks. Query injection isn't defended against; it's unrepresentable. Every query runs sandboxed with timeouts and result caps.
Cost controls
Hard spend caps apply per investigation and per tenant per day, alongside per-stage timeouts and tool-call limits. These live in the engine, so hitting a cap stops the work rather than the invoice being a surprise later. When a cap is reached you still receive a report with the evidence gathered up to that point.
Data handling
We store the alerts you send us, the investigations they produce, and the reports we deliver — plus the runbooks and postmortems you give us, indexed so investigations can cite them. Telemetry is queried at investigation time; we keep the query results that appear as evidence in a report, not a copy of your metrics store.
What we deliberately don't do
Nightswatch does not act on your systems: there is no auto-remediation, so nothing it concludes can change your production state. We don't offer uptime guarantees, we don't deploy on-prem, and we don't claim compliance certifications we haven't earned. If any of those are hard requirements today, we'd rather tell you now.

Questions we haven't answered here? gurbakshsinghgabbi@gmail.com