Security

NightWatch is built for solo developers and private paid beta customers who run Claude Code, Codex CLI, and similar tools on infrastructure they control.

NightWatch does not host workers. Your code runs on your own computer, server, or VPS, and each paired worker uses its own revocable token from the Workers page.

Claude/Codex credentials stay on your worker when using local CLI execution. NightWatch sends approved task prompts to the paired worker and receives heartbeats, logs, task status, and completion events.

NightWatch does not need your local Claude/Codex login or API key for worker execution. Do not paste local CLI credentials, repository deploy keys, or third-party AI credentials into task descriptions, session names, logs, or support messages.

GitHub import credentials are used once and are not stored. Use a limited-scope personal access token for private repositories and revoke it from GitHub when it is no longer needed.

Session logs are retained for 90 days unless removed earlier. Support exports redact common secret formats before sharing evidence.

NightWatch is not claiming SOC 2, enterprise compliance, hosted secure compute, or managed AI execution during the private paid beta.

To report a security concern, email security@veraminds.com.