Security and Privacy Controls Overview
This Security and Privacy Controls Overview summarizes technical and organizational measures MiseCentral LLC ("MiseCentral," "we," "us," or "our") implements to protect Customer Data, including Personal Data, in connection with the Services. This overview supplements the Agreement, Data Processing Agreement ("DPA"), and related policies. It describes controls consistent with MiseCentral's platform design and operational practices. It is not a certification statement unless expressly identified in a separate attestation.
1. Governance and Program
1.1. MiseCentral maintains documented security and privacy policies, assigns ownership for security functions, and reviews risks relevant to the Services on a recurring basis.
1.2. Personnel with access to production Customer Data receive security and privacy training appropriate to their roles.
1.3. MiseCentral evaluates Subprocessors for security and privacy practices before engagement and through ongoing oversight as described in the Subprocessor Policy.
2. Access Control
2.1. Authentication. Authorized Users authenticate through Customer-managed credentials and configurable authentication policies. MiseCentral personnel access production systems through controlled accounts with multi-factor authentication.
2.2. Authorization. Role-based access controls within the Services limit Authorized User permissions according to Customer-assigned roles and hospitality operational profiles.
2.3. Least Privilege. MiseCentral limits internal access to Customer Data to personnel with a documented need for support, security, or engineering purposes.
2.4. Support Mode Controls. Support Mode and Partner Support Mode sessions are temporary, ticket-bound, reason-coded, duration-limited, and logged. Support personnel do not impersonate Customer users. See the Support Mode Policy.
3. Encryption and Data Protection
3.1. In Transit. Customer Data transmitted between users and the Services is protected using TLS.
3.2. At Rest. Customer Data stored in MiseCentral production environments is encrypted at rest using industry-standard mechanisms provided by underlying cloud infrastructure.
3.3. Secrets Management. API keys, Service Account credentials, and integration secrets are stored using secure vault mechanisms with access restricted to authorized systems and personnel.
4. Application and Infrastructure Security
4.1. Secure Development. MiseCentral follows secure development practices including code review, change management, and pre-production testing for material changes.
4.2. Vulnerability Management. MiseCentral monitors for vulnerabilities in dependencies and infrastructure and remediates material issues according to severity-based timelines.
4.3. Environment Segregation. Production environments are logically separated from non-production environments. Customer Data is not used in non-production environments except in sanitized or Customer-authorized test configurations.
4.4. Cloud Infrastructure. The Services operate on reputable cloud infrastructure with physical and environmental controls appropriate to hosted SaaS operations.
5. Logging, Monitoring, and Operational Evidence
5.1. The Services maintain audit logs for administrative actions, authentication events, configuration changes, Support Mode activity, and API usage attributable to accounts.
5.2. MiseCentral monitors platform telemetry for availability, performance anomalies, and indicators of unauthorized access.
5.3. Operational Evidence retained in the Services supports Customer accountability for hospitality workflows, quality records, and traceability activities.
6. Incident Response and Breach Notification
6.1. MiseCentral maintains an Incident Response Policy with procedures for identification, containment, investigation, remediation, and notification.
6.2. Personal Data breach notification to Customer is provided as described in the DPA and Incident Response Policy.
7. Business Continuity and Disaster Recovery
7.1. MiseCentral maintains backup and disaster recovery capabilities as described in the Business Continuity Policy, Disaster Recovery Statement, and Service Availability Policy.
7.2. Recovery objectives are defined at the platform level and may vary by subscription tier or Order Form.
8. Data Minimization and Retention
8.1. MiseCentral processes Customer Data only as necessary to provide the Services and as described in the DPA, Privacy Notice, Data Retention Policy, and Data Deletion Policy.
8.2. Customer may configure certain retention and deletion settings within the Services where available.
9. Privacy by Design
9.1. Product features incorporate role-based visibility, configurable integrations, and administrative controls intended to help Customer govern operational and workforce data.
9.2. Operational Recommendations are advisory. Explainability and history features support Customer review without replacing Customer's compliance obligations.
9.3. MiseCentral does not use Customer Data to train foundation models for unrelated customers unless Customer provides documented authorization.
10. Customer Responsibilities
10.1. Customer is responsible for:
(a) configuring roles, permissions, and integrations appropriately for its facilities; (b) managing Authorized User access and seat licensing; (c) establishing lawful bases and notices for Personal Data Customer submits; (d) maintaining food-safety, quality, traceability, and employment compliance in its operations; (e) reviewing advisory Operational Recommendations before acting; and (f) securing Customer-managed endpoints, Connected Devices, and Connected Service credentials.
11. Enterprise and Audit Information
11.1. Customers may request additional security documentation, completed questionnaires, or audit information as described in the DPA and Support Policy.
11.2. Independent audit reports or certifications will be made available to enterprise Customers when obtained and appropriate under confidentiality restrictions.
12. Explicit Non-Claims
12.1. Unless separately stated in a written attestation, this overview does not represent completion of SOC 2 Type II certification, PCI DSS certification, HIPAA compliance as a covered entity or business associate, or other third-party certification.
13. Contact
Security inquiries: MiseCentral LLC Attn: Security 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com
Privacy inquiries: privacy@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.