How Night Porter handles your data

Night Porter runs one repeatable job for US staffing and consulting firms. This page is for whoever checks our security.

What do you read?
[Systems by name, confirmed per engagement in the statement of work]
What do you write?
Only items a person on your team has approved, and only to fields named in the statement of work.
Whose credentials?
Scoped to the workflow, held in your accounts wherever the vendor allows, and revocable by you without contacting us.
Do AI providers train on our data?
[Named providers and their training and retention terms]
Where is data hosted?
[Hosting provider and region]
Is it encrypted?
[In transit and at rest: confirm]
Is there an audit log?
[What is logged, and who can see it]
Is our data separate from other clients?
[Confirm with the technical founder in writing]
How long do you keep it?
[Retention schedule and deletion window]
Where is your team?
[International transfer line]
Do you hold certifications?
Not yet. We don't hold SOC 2 or ISO 27001. We'll send our written security practice on request.
Data-processing terms:
[Link]
Security contact:
[Email]