Trust

Your data is yours — we just keep it safe.

This page is maintained by Nightingale Software Group as a plain-English overview of how we protect customer data. It is not an independent certification.

Security & trust

Security and trust, in plain English.

What we actually do to protect your data — no badges we haven't earned.

  • Secure by design
  • Multi-tenant isolation
  • Role-based access
  • Audit trails
  • SSO via Admin Centre
  • AI assistance, opt-in

UK hosting and jurisdiction

Customer data is held in UK and EU regions and Nightingale Software Group is a UK company, registered with the ICO. Contracts and disputes are governed by the law of England and Wales.

Encryption

Traffic is encrypted in transit with TLS, and data is encrypted at rest in the database and in file storage. Secrets and API keys are stored separately from application data.

Daily backups

The database is backed up daily with point-in-time recovery, so a mistake on your side or ours can be rolled back rather than lived with.

Audit logs

Significant actions — record changes, approvals, exports, permission changes — are written to an audit trail with the user and timestamp attached.

Role-based permissions

Access is granted by role, enforced at the database row level, so people only ever see the records their role allows. Admins can review and change roles at any time.

Multi-tenant isolation

Every organisation's data is separated at the database level. One tenant cannot read another tenant's records, and that is enforced by the platform rather than by application code alone.

Availability

Apps run on managed, redundant infrastructure with automated health checks. Planned maintenance is communicated in advance; Enterprise customers can agree a written service level.

Support

Email support on every plan including the free tier, priority response on Pro, and a named contact with an agreed response time on Enterprise.

GDPR and data protection

You remain the data controller for your business data; we act as processor. A DPA is available, personal data requests are supported, and retention periods can be configured per workspace.

The legal stack

Read the underlying documents.

Contact

Report a security issue.

If you believe you've found a security issue, email security@nightingalesoftware.co.uk. We'll acknowledge within one business day.

Images are indicative of the product only and do not necessarily represent the final app appearance.