Your data is yours — we just keep it safe.
This page is maintained by Nightingale Software Group as a plain-English overview of how we protect customer data. It is not an independent certification.
Security and trust, in plain English.
What we actually do to protect your data — no badges we haven't earned.
- Secure by design
- Multi-tenant isolation
- Role-based access
- Audit trails
- SSO via Admin Centre
- AI assistance, opt-in
UK hosting and jurisdiction
Customer data is held in UK and EU regions and Nightingale Software Group is a UK company, registered with the ICO. Contracts and disputes are governed by the law of England and Wales.
Encryption
Traffic is encrypted in transit with TLS, and data is encrypted at rest in the database and in file storage. Secrets and API keys are stored separately from application data.
Daily backups
The database is backed up daily with point-in-time recovery, so a mistake on your side or ours can be rolled back rather than lived with.
Audit logs
Significant actions — record changes, approvals, exports, permission changes — are written to an audit trail with the user and timestamp attached.
Role-based permissions
Access is granted by role, enforced at the database row level, so people only ever see the records their role allows. Admins can review and change roles at any time.
Multi-tenant isolation
Every organisation's data is separated at the database level. One tenant cannot read another tenant's records, and that is enforced by the platform rather than by application code alone.
Availability
Apps run on managed, redundant infrastructure with automated health checks. Planned maintenance is communicated in advance; Enterprise customers can agree a written service level.
Support
Email support on every plan including the free tier, priority response on Pro, and a named contact with an agreed response time on Enterprise.
GDPR and data protection
You remain the data controller for your business data; we act as processor. A DPA is available, personal data requests are supported, and retention periods can be configured per workspace.
Read the underlying documents.
Report a security issue.
If you believe you've found a security issue, email security@nightingalesoftware.co.uk. We'll acknowledge within one business day.
