Skip to content
MiseCentral
Platform Overview Work Intelligence Product Tour Technology Profile Integrations Implementation Enterprise Administration
Solutions Overview Capabilities Overview Recipes Production Operations Inventory Purchasing Quality Traceability Food Safety Labor Planning Company Brain
All Industries Restaurants Hospitality Catering Production Retail Food Distribution
Work Intelligence Trust
Resource Center Customer Stories ROI Pricing Support
About How We Operate Media Trust Center Procurement Contact
Sign In Book a Demo
Home · Security · Security Overview

Security Overview

High-level security practices for the Services.

Version
1.0
Effective
August 1, 2026
Last updated
August 1, 2026
Document ID
LEGAL-PUB-005
Download PDF Contact Legal Contact Privacy

On this page

  1. 1. Security Program
  2. 2. Infrastructure and Architecture
  3. 3. Identity, Access, and Authentication
  4. 4. Application and Operational Security
  5. 5. Monitoring, Logging, and Incident Response
  6. 6. Vendor and Subprocessor Management
  7. 7. Customer Responsibilities
  8. 8. Compliance and Assessments
  9. 9. Reporting Security Issues
  10. 10. Updates

All legal documents

Security Overview

This Security Overview describes MiseCentral LLC's ("MiseCentral") administrative, technical, and organizational security practices for the Services and related infrastructure. It is a summary for customers and prospects and does not modify any Agreement, Order Form, SLA, or DPA. Detailed commitments appear in those documents and in Documentation provided to Customers.

1. Security Program

1.1. MiseCentral maintains a security program designed to protect Customer Data, including operational, quality, food-safety, traceability, and workforce-configuration records processed in our hospitality operations platform.

1.2. Our program includes risk management, secure development practices, access controls, monitoring, incident response, vendor management, and workforce training appropriate to the nature of the Services.

1.3. MiseCentral may update security controls as threats, regulations, and platform capabilities evolve.

2. Infrastructure and Architecture

2.1. The Services are hosted on industry-standard cloud infrastructure with geographically distributed data centers operated by reputable cloud providers.

2.2. Production environments are logically separated from non-production environments. Network security controls, including firewalls and segmentation, restrict access to systems processing Customer Data.

2.3. Encryption in transit is implemented using current industry protocols for external connections and internal service communications where applicable.

2.4. Encryption at rest is applied to stored Customer Data in production systems using industry-standard methods.

3. Identity, Access, and Authentication

3.1. Customer Controls. Customers configure roles, permissions, seat assignments, and access policies for Authorized Users, Service Accounts, API Clients, Connected Devices, and delegated Partner administration.

3.2. MiseCentral Workforce Access. MiseCentral personnel access Customer environments only through Support Mode or other governed mechanisms that are ticket-bound, reason-coded, time-limited, and audited. Support Mode does not permit impersonation of Customer users.

3.3. Partner Support Mode. Authorized Partners may assist Customers through Partner Support Mode under active delegation, subject to audit logging and Customer visibility.

3.4. Authentication. The Services support strong authentication options, including multi-factor authentication for administrative and support access as configured. Customers are responsible for credential hygiene and timely deprovisioning of Authorized Users.

4. Application and Operational Security

4.1. MiseCentral employs secure software development practices, code review, dependency management, and vulnerability remediation processes.

4.2. Operational Intelligence features, including Company Brain and Work Intelligence, operate within Customer-configured permissions and retain Operational Evidence and audit history to support accountability.

4.3. Changes to production systems follow controlled release and change-management procedures.

4.4. Backups and recovery procedures are maintained to support business continuity and data restoration objectives described in the Agreement and Documentation.

5. Monitoring, Logging, and Incident Response

5.1. We monitor infrastructure and applications for security events, anomalous activity, and service integrity.

5.2. Security and operational logs support investigation, audit, and Customer visibility features where enabled.

5.3. MiseCentral maintains an incident response process to assess, contain, remediate, and notify affected parties of Security Incidents involving Customer Personal Data as required by the Agreement and applicable law.

6. Vendor and Subprocessor Management

6.1. MiseCentral engages Subprocessors for hosting, infrastructure, communications, and operational support. Subprocessors are subject to contractual security and confidentiality obligations.

6.2. A list of Subprocessors is available to Customers under the DPA.

7. Customer Responsibilities

7.1. Security is a shared responsibility. Customers are responsible for:

(a) configuring roles, permissions, and integrations appropriately; (b) managing Authorized Users, Service Accounts, API Clients, and Connected Devices; (c) maintaining endpoint security for devices accessing the Services; (d) reviewing Operational Recommendations and alerts before acting; (e) governing Connected Services and data exchanged through integrations; and (f) complying with applicable laws in their facilities and jurisdictions.

7.2. Customers must promptly notify MiseCentral of suspected unauthorized access or credential compromise.

8. Compliance and Assessments

8.1. MiseCentral designs controls with common enterprise expectations in mind, including SOC 2-aligned control themes and GDPR Article 32 security-of-processing principles for Customer Personal Data.

8.2. Formal third-party attestation reports, penetration test summaries, and security questionnaires may be available to Customers under NDA as described in the Agreement or enterprise security addenda.

8.3. This Security Overview does not represent completion of any specific certification unless expressly stated in a written attestation shared with Customer.

9. Reporting Security Issues

9.1. Security researchers, Customers, and other parties may report suspected vulnerabilities or security concerns to:

MiseCentral LLC Attn: Security 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com

9.2. Please include sufficient detail for reproduction and allow reasonable time for investigation before public disclosure. MiseCentral does not authorize testing that disrupts production systems or accesses data without authorization.

10. Updates

10.1. We may update this Security Overview to reflect material changes in our practices. The "Last Updated" date will indicate the latest revision.

Version history

VersionEffectiveSummary
1.0August 1, 2026Initial publication of the Legal Library (LEGAL-01).

Previous versions remain available for reference and are never overwritten.

MiseCentral

The Adaptive Operating System for Hospitality—smoother operations, adaptive intelligence, and people in command.

Product

Product Tour Platform Work Intelligence Solutions Industries Pricing

Trust

Trust Center Legal Privacy Security Status Responsible AI

Company

About Resources Support Procurement Contact Book a Demo
© MiseCentral LLC. All rights reserved. · Terms · Privacy · Cookies · Trust Center · Trademark