Frequently Asked Questions (FAQs)

How fast does Nightfall see a new Claude message?

Conversations and files are polled every 60 seconds; the activity feed is polled every 30 seconds. [verify] Cadence with engineering against PRD §9b.

What happens if a user deletes content in Claude?

The connector best-effort propagates deletes to the Nightfall index. [verify] Deletion-propagation semantics with Anthropic. Tracked as PRD §14 open question 5.

Can I keep finding metadata but drop the raw Claude conversation text?

Yes. Enable redaction-at-ingest mode on the integration. Findings, detector hits, and byte offsets are preserved; the raw content is not stored. See PRD US-18.

Where can I see Claude admin activity?

The Claude Activity view in Nightfall. Events also forward to your SIEM destination if you have one configured.

Can I block a prompt before it reaches Claude?

Not via the Compliance API. Use the Nightfall endpoint agent for inline block on Claude Desktop, Claude Code, or the Claude browser tab. (Linked above.)

Will this cover Claude on Bedrock or Vertex AI?

No. Those surfaces are not exposed by the Compliance API. Use the Nightfall endpoint agent on the developer's machine, or the AI Agent Security integration if the work is happening inside Claude Code.

Last updated

Was this helpful?