Logging and Audit Policy
This Logging and Audit Policy ("Policy") describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") generates, protects, retains, and makes available audit records and security logs for the Services. This Policy supports accountability, incident investigation, Customer visibility, and Operational Evidence integrity.
Capitalized terms not defined herein have the meanings set forth in the MiseCentral Legal Library Defined Terms or the applicable Agreement.
1. Purpose and Scope
1.1. Purpose. MiseCentral maintains logging and audit capabilities to record security-relevant events, administrative actions, assistance sessions, integration activity, and operational mutations with attributable actors and timestamps.
1.2. Scope. This Policy covers:
(a) audit logs and Operational Evidence within the Services visible to Customers;
(b) platform security logs for authentication, authorization, Support Mode, and Partner Support Mode;
(c) infrastructure and application logs supporting security monitoring; and
(d) commercial billing audit events related to security configuration such as MFA policy changes.
2. Logging Principles
2.1. Attribution. Audit records identify the acting party where known: Authorized User, Service Account, API Client, MiseCentral staff user in Support Mode, or Partner User in Partner Support Mode.
2.2. Integrity. Audit records are protected against casual tampering through access controls and system design. Customers cannot alter MiseCentral platform audit history for Support Mode sessions.
2.3. Minimization of Secrets. Logs and audit exports exclude passwords, raw tokens, secrets, and key material. Replay and assistance views sanitize sensitive metadata keys.
2.4. Tenant Isolation. Logs are scoped to organizations. MiseCentral staff access to logs follows organization scoping and Support Mode requirements.
2.5. Customer Visibility. Events material to Customer governance, including Support Mode announcements, assistance records designated customer-visible, delegation changes, and security policy updates, are exposed through Customer-accessible interfaces described in Documentation.
3. Events Logged
3.1. Authentication and MFA. Login successes and failures, MFA enrollment and verification, password resets, session termination, and organization MFA policy changes.
3.2. Authorization and Administration. Role assignments, permission changes, seat assignment changes, organization setting modifications, and API Client or Service Account lifecycle events.
3.3. Support Mode. Session start and end, ticket linkage, reason codes, duration, acting staff identity, MFA satisfaction, mutations performed during assistance, and customer-visible assistance records.
3.4. Partner Support Mode. Session start and end, delegation reference, ticket linkage, acting Partner User identity, MFA satisfaction, and mutations within delegation scope.
3.5. Integrations. Connected Service authorization, revocation, Connected Device registration changes, and anomalous integration patterns where detected.
3.6. Operational Evidence. Operational mutations material to hospitality workflows, quality records, food-safety documentation, traceability events, and attachments, including timestamps and actor attribution as configured in Customer workflows.
3.7. Commercial Security Events. MFA policy changes may generate commercial billing audit events and organization audit log entries with impact metadata.
3.8. Platform Operations. Internal staff actions on platform routes are logged with staff identity for accountability.
4. Operational Evidence
4.1. Operational Evidence consists of records, attachments, timestamps, attributions, and audit artifacts retained in the Services to document operational activity.
4.2. Operational Evidence supports Customer regulatory, quality, and food-safety programs. MiseCentral hosts Operational Evidence as part of Customer Data under Customer ownership.
4.3. Operational Recommendations and Company Brain outputs may reference Operational Evidence but do not replace original records. Customers remain responsible for verifying recommendations against source evidence.
4.4. Retention of Operational Evidence follows Customer configuration, Agreement terms, and the Record Retention Policy where applicable to MiseCentral's hosting obligations.
5. Log Protection and Access
5.1. Access Controls. Access to production logs is limited to authorized MiseCentral personnel on a need-to-know basis. Access is logged.
5.2. Customer Access. Customer administrators and authorized roles may access organization audit history and Operational Evidence through the Services as described in Documentation.
5.3. Partner Access. Partners access audit information only within delegated scope and Partner Support Mode context. Partners do not receive access to billing audit logs unless commercially authorized.
5.4. Legal Process. MiseCentral responds to lawful requests for log data consistent with the Agreement, DPA, and applicable law, providing Customer notice where permitted.
6. Retention
6.1. Platform Security Logs. Infrastructure and security monitoring logs are retained for periods defined by MiseCentral internal retention schedules, balanced against investigation needs, storage cost, and legal obligations.
6.2. Customer-Visible Audit Logs. Organization audit history available in the Services is retained according to Subscription plan, Documentation, and Agreement terms.
6.3. Operational Evidence. Retention defaults and Customer-configurable retention settings are described in Documentation and the Record Retention Policy.
6.4. Deletion. Upon termination of an Agreement, MiseCentral deletes or returns Customer Data including Operational Evidence per the Agreement and DPA, subject to legal retention exceptions.
7. Monitoring and Alerting
7.1. MiseCentral monitors logs and metrics for indicators of compromise, abuse, authentication anomalies, and Service health.
7.2. Alerts route to on-call personnel according to internal runbooks. Confirmed incidents follow the Information Security Policy incident response procedures.
7.3. Customers may configure notifications for certain operational and security events as described in Documentation.
8. Export and Enterprise Requests
8.1. Customers may export audit and Operational Evidence through import/export tooling where enabled, subject to role permissions and Agreement terms.
8.2. Enterprise Customers may request additional log support during security investigations subject to mutual cooperation, confidentiality, and reasonable scope limits.
9. Clock Synchronization
9.1. Production systems use synchronized time sources to ensure consistent timestamps across audit records and Operational Evidence.
10. Policy Review
10.1. This Policy is reviewed at least annually and upon material logging architecture changes.
11. Contact
MiseCentral LLC Attn: Security — Audit 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.