Skip to content
MiseCentral
Platform Overview Work Intelligence Product Tour Technology Profile Integrations Implementation Enterprise Administration
Solutions Overview Capabilities Overview Recipes Production Operations Inventory Purchasing Quality Traceability Food Safety Labor Planning Company Brain
All Industries Restaurants Hospitality Catering Production Retail Food Distribution
Work Intelligence Trust
Resource Center Customer Stories ROI Pricing Support
About How We Operate Media Trust Center Procurement Contact
Sign In Book a Demo
Home · Security · Information Security Policy

Information Security Policy

Information security management policy.

Version
1.0
Effective
August 1, 2026
Last updated
August 1, 2026
Document ID
LEGAL-SEC-001
Download PDF Contact Legal Contact Privacy

On this page

  1. 1. Purpose and Scope
  2. 2. Security Governance
  3. 3. Security Principles
  4. 4. Organizational Security
  5. 5. Technical and Operational Controls
  6. 6. Data Protection
  7. 7. Connected Services, Devices, and Integrations
  8. 8. Incident Response
  9. 9. Business Continuity
  10. 10. Security Assessments and Improvement
  11. 11. Policy Compliance
  12. 12. Contact

All legal documents

Information Security Policy

This Information Security Policy ("Policy") describes MiseCentral LLC's ("MiseCentral," "we," "us," or "our") security principles, governance, and commitments for the Services and related operations. This Policy applies to MiseCentral personnel, contractors with access to MiseCentral systems, and is made available to Customers and Partners as part of MiseCentral's security transparency program.

This Policy supplements, and does not replace, binding commercial agreements. Capitalized terms not defined herein have the meanings set forth in the MiseCentral Legal Library Defined Terms or the applicable Agreement.

1. Purpose and Scope

1.1. Purpose. MiseCentral operates an enterprise hospitality operations platform that hosts Customer Data, including operational, quality, food-safety, traceability, and workforce-configuration records. This Policy establishes the security objectives, control framework, and accountability structures MiseCentral maintains to protect the confidentiality, integrity, and availability of the Services and Customer Data.

1.2. Scope. This Policy covers:

(a) the hosted Services, including Adaptive Operational Intelligence, Company Brain, Work Intelligence, Operational Intelligence, Adaptive Scheduling, Adaptive Work Execution, Operational State, Support Mode, Partner Support Mode, Connected Services and Connected Device governance, Marketplace (where enabled), migration and import/export tooling, and related infrastructure;

(b) MiseCentral-operated production, staging, and corporate systems that process Customer Data or credentials;

(c) MiseCentral personnel and authorized contractors; and

(d) Subprocessors and vendors that process Customer Data on MiseCentral's behalf, as further described in the Vendor Security Policy.

1.3. Customer Responsibilities. Customers remain responsible for configuring organization security settings, assigning appropriate roles and seats, governing Connected Services and Connected Devices, evaluating Operational Recommendations, and maintaining security within their facilities and third-party integrations. Customer-specific security obligations appear in the Agreement, Documentation, and applicable Order Form.

2. Security Governance

2.1. Ownership. MiseCentral's executive leadership assigns overall accountability for information security. Day-to-day security operations, incident response coordination, and control maintenance are managed by MiseCentral's security function in coordination with engineering, operations, and legal.

2.2. Policy Library. MiseCentral maintains a modular security policy library, including policies for access control, authentication, multi-factor authentication, secure development, logging and audit, vendor security, and vulnerability disclosure. Policies are reviewed at least annually and upon material changes to the Services, threat landscape, or regulatory environment.

2.3. Risk Management. MiseCentral identifies, assesses, and treats security risks using a risk-based approach proportionate to the nature of the Services and data processed. Risk treatment decisions are documented and tracked to resolution or accepted residual risk with appropriate approval.

2.4. Compliance Alignment. MiseCentral designs security controls with reference to recognized frameworks and industry practice for enterprise B2B SaaS. MiseCentral does not represent that any specific certification or attestation has been completed unless expressly stated in a separate written attestation or Order Form.

3. Security Principles

3.1. Defense in Depth. MiseCentral employs layered technical and organizational controls across network boundaries, application logic, data stores, identity systems, and operational processes.

3.2. Least Privilege. Access to systems and Customer Data is granted on a need-to-know, need-to-use basis, with role-based permissions and time-bound elevation where appropriate.

3.3. Secure by Design. Security requirements are integrated into architecture, development, deployment, and change management for the Services.

3.4. Transparency and Auditability. Security-relevant actions, including Support Mode and Partner Support Mode sessions, role changes, and administrative configuration changes, generate attributable audit records visible to authorized parties as described in the Logging and Audit Policy and Documentation.

3.5. No Impersonation. MiseCentral staff and Partners assist Customers through Support Mode and Partner Support Mode, respectively. These mechanisms do not permit silent impersonation of Customer users. Assistance sessions are ticket-linked, reason-coded, duration-limited, and customer-visible.

3.6. Customer Data Ownership. Customer retains all right, title, and interest in Customer Data. MiseCentral processes Customer Data solely under the limited license and instructions set forth in the Agreement and DPA.

4. Organizational Security

4.1. Personnel Security. MiseCentral personnel with access to production systems or Customer Data undergo background screening commensurate with role sensitivity and applicable law. Personnel receive security awareness training upon hire and periodically thereafter.

4.2. Confidentiality. Personnel and contractors with access to Confidential Information are bound by confidentiality obligations consistent with MiseCentral's internal policies and applicable agreements.

4.3. Acceptable Use. Use of MiseCentral technology resources by personnel is governed by internal acceptable use policies. Violations may result in disciplinary action and termination of access.

5. Technical and Operational Controls

5.1. Infrastructure Security. Production environments are segmented from non-production environments. Network access controls, encryption in transit, and encryption at rest for Customer Data are implemented using industry-standard mechanisms described in Documentation and security summaries provided to enterprise Customers upon request.

5.2. Identity and Access Management. Authentication, authorization, multi-factor authentication, and session management are governed by the Authentication Policy, MFA Policy, and Access Control Policy.

5.3. Application Security. Secure development practices, code review, dependency management, and vulnerability remediation are governed by the Secure Development Policy.

5.4. Logging and Monitoring. Security events, administrative actions, and Support Mode activity are logged and retained as described in the Logging and Audit Policy.

5.5. Backup and Recovery. MiseCentral maintains backup and recovery procedures designed to support data integrity and service restoration. Recovery objectives are defined internally and tested on a periodic basis.

5.6. Change Management. Material changes to production systems follow documented change management procedures including review, approval, and rollback planning appropriate to change risk.

6. Data Protection

6.1. Classification. Customer Data is treated as confidential business data of the Customer. MiseCentral's internal data classification standards govern MiseCentral-owned materials and operational records.

6.2. Processing Limitations. MiseCentral does not use Customer Data to train foundation models for unrelated customers unless Customer provides documented authorization or the data constitutes Aggregated Data that cannot reasonably identify Customer, as stated in the Agreement.

6.3. Subprocessors. MiseCentral engages Subprocessors under written agreements imposing data protection and security obligations consistent with the DPA. A current Subprocessor list is made available as described in the DPA.

6.4. Data Location and Transfers. Customer Data is processed in regions and facilities described in Documentation or the DPA. International transfers of Personal Data, where applicable, are addressed in the DPA and applicable transfer mechanisms.

7. Connected Services, Devices, and Integrations

7.1. Customer Governance. Customers control registration and authorization of Connected Services, Connected Devices, API Clients, and Service Accounts through organization governance controls described in Documentation.

7.2. Integration Security. MiseCentral implements controls to validate integration credentials, scope API access, and monitor anomalous integration activity. Customers are responsible for securing credentials and permissions on systems they connect to the Services.

7.3. Marketplace. Where Marketplace is enabled, third-party offerings are subject to MiseCentral's partner and marketplace governance programs. MiseCentral does not warrant third-party offerings unless expressly stated in writing.

8. Incident Response

8.1. Program. MiseCentral maintains an incident response program to detect, contain, investigate, remediate, and learn from security incidents affecting the Services or Customer Data.

8.2. Customer Notification. Where MiseCentral determines that a confirmed security incident has compromised the security of Customer Data processed by MiseCentral, MiseCentral will notify affected Customers without undue delay and in accordance with the Agreement, DPA, and applicable law.

8.3. Cooperation. MiseCentral will cooperate with Customers in investigating incidents within the scope of MiseCentral's control, subject to confidentiality, legal, and operational constraints.

8.4. Support Mode in Incidents. Where Support Mode or Partner Support Mode is used during incident response, such access follows the same ticket-linked, audited, and customer-visible requirements as routine support assistance.

9. Business Continuity

9.1. MiseCentral maintains business continuity and disaster recovery planning proportionate to the Services. Availability commitments, if any, appear in the SLA attached to the Customer's Agreement.

9.2. Operational Recommendations, alerts, and insights generated by the Services are advisory. Customers remain responsible for operational continuity decisions in their facilities.

10. Security Assessments and Improvement

10.1. MiseCentral conducts internal security assessments, vulnerability management, and penetration testing on a risk-based schedule. Results inform remediation priorities and control improvements.

10.2. Enterprise Customers may request security documentation, questionnaires, or audit cooperation subject to the Agreement, mutual confidentiality arrangements, and reasonable frequency limits.

11. Policy Compliance

11.1. MiseCentral personnel and authorized contractors must comply with this Policy and related security policies. Non-compliance must be reported through internal channels or the security contact below.

11.2. MiseCentral may update this Policy by posting a revised version with an updated Effective Date and Last Updated date. Material changes affecting Customer-facing commitments will be communicated as described in the Agreement or Documentation.

12. Contact

Security inquiries, documentation requests, and incident reports may be directed to:

MiseCentral LLC Attn: Security 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com

Legal inquiries: legal@misecentral.com

Version history

VersionEffectiveSummary
1.0August 1, 2026Initial publication of the Legal Library (LEGAL-01).

Previous versions remain available for reference and are never overwritten.

MiseCentral

The Adaptive Operating System for Hospitality—smoother operations, adaptive intelligence, and people in command.

Product

Product Tour Platform Work Intelligence Solutions Industries Pricing

Trust

Trust Center Legal Privacy Security Status Responsible AI

Company

About Resources Support Procurement Contact Book a Demo
© MiseCentral LLC. All rights reserved. · Terms · Privacy · Cookies · Trust Center · Trademark