Privacy Policy
NightShift, operated by Skripted LLC
Last updated: June 2026
This policy explains what personal data we collect, why, who we share it with, and the choices you have. It covers two different situations: visitors to our website, and customers whose systems we test. If anything here conflicts with a signed agreement between us, that agreement controls.
1. Who we are
NightShift is a penetration testing service operated by Skripted LLC. For questions about this policy or your data, contact us at hello at nightshiftsec dot ai.
2. Data we collect
From website visitors. If you submit our contact or lead-capture form, we collect the information you provide, typically your name, email address, and any message. We also collect basic technical and analytics data automatically, such as your IP address, browser type, and pages viewed.
From customers during an engagement. To deliver a penetration test, we process data about the systems you authorize us to test. This may include URLs, request and response data, headers, and any vulnerabilities or technical details discovered. Findings about your systems are treated as your confidential information.
We do not seek to collect sensitive personal data (such as health records, payment card data, or government identification numbers), and you should not deliberately provide it to us.
3. Why we use it
- To respond to your inquiries and follow up on your interest in our service
- To perform penetration testing you have authorized and deliver your report
- To operate, maintain, secure, and improve our website and service
- To send you service-related communications
- To comply with legal obligations
We do not sell your personal data.
4. Who we share it with
We share data only with service providers that help us operate, and only as needed:
- Hosting and infrastructure — Amazon Web Services (AWS), where our website and databases run.
- Email — Resend, which delivers our transactional email (such as verification codes and report notifications). The intake details you submit are stored in our own AWS infrastructure, not a third-party form tool.
- Payments — Stripe, which processes payments and handles your card details directly under its own privacy policy. We do not receive or store full card numbers.
- Analytics — Google Analytics, loaded and managed through Google Tag Manager, to understand how visitors use our site.
- Third-party AI services — to analyze testing results, target response data may be processed by AI providers (such as Anthropic and OpenAI) under their own terms. We do not intentionally send credentials or secrets discovered during testing to these providers.
- Legal and safety — where required by law, or to protect our rights.
We do not otherwise disclose your data to third parties without your consent.
5. How long we keep it
We keep lead and contact data for as long as needed to respond to you and for our legitimate business records, then delete it. We retain engagement data and reports for up to 12 months after delivery — aligned with the report validity period in our Terms of Service — after which we delete them, unless you ask us to delete them sooner. We may keep anonymized, non-identifying technical data to improve our service.
6. How we protect it
We use reasonable technical and organizational measures to protect personal data, including encryption in transit (TLS) and at rest, scoped access controls, and network restrictions on our infrastructure. Any test-account credentials you share for an engagement are encrypted in your browser before they reach us, so we store only ciphertext and cannot read them. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us at hello at nightshiftsec dot ai and we will respond as required by applicable law.
California residents (CCPA/CPRA): You may have the right to know what personal information we collect, to access or delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined under California law.
EEA / UK residents (GDPR / UK GDPR): Where the GDPR or UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. We process your data on the basis of your consent, our legitimate interests in operating and securing our service, and where necessary to perform a contract with you.
8. Cookies and tracking
Our site uses essential cookies needed for the funnel to work — for example, to keep you signed in while you complete checkout — and cookies set by Stripe to process payments and help prevent fraud. We also use Google Analytics, loaded through Google Tag Manager, which sets cookies to measure how visitors use the site. You can opt out of Google Analytics with Google's browser add-on, or block cookies in your browser settings.
9. Changes to this policy
We may update this policy from time to time. The current version will always be posted here with its effective date.
10. Governing law
This policy is governed by the laws of the State of New York, USA, consistent with our Terms of Service.