Back to features Set up encryptionStep-by-step instructions in the documentation.
Encryption
Appeals contain the most sensitive things members ever tell you: mental health, personal circumstances, accusations against other members. Nighthawk encrypts them in the submitter’s browser, to a key only your team holds, so neither Nighthawk nor its database can read them.
What you get
- Appeals encrypted in the browser, before they are ever sent
- Only staff holding your community’s key can read them
- Case reasons, deleted messages and audit details stored as ciphertext
- Passphrase-protected key backups, restorable on any device
How it works
Publish an encryption key from the dashboard and your browser generates the keypair, keeping the private half locally. From then on a banned member’s browser locks their appeal to your public key before it leaves their machine.
Generating forces a passphrase-protected backup: one file downloaded, one copy stored against your Nighthawk account. Both are useless without the passphrase, and Nighthawk cannot reset it.
Separately, sensitive moderation data is encrypted before it reaches the database: case reasons, saved and deleted message content, incident replays, automod matches, audit details, username history and persisted roles.
Watchlist report reasons stay readable by design, because they are shared with other communities. The Encryption page in your dashboard lists exactly what falls under each layer.