Skip to content
MiseCentral
Platform Overview Work Intelligence Product Tour Technology Profile Integrations Implementation Enterprise Administration
Solutions Overview Capabilities Overview Recipes Production Operations Inventory Purchasing Quality Traceability Food Safety Labor Planning Company Brain
All Industries Restaurants Hospitality Catering Production Retail Food Distribution
Work Intelligence Trust
Resource Center Customer Stories ROI Pricing Support
About How We Operate Media Trust Center Procurement Contact
Sign In Book a Demo
Home · Security · Vendor Security Policy

Vendor Security Policy

Vendor security expectations.

Version
1.0
Effective
August 1, 2026
Last updated
August 1, 2026
Document ID
LEGAL-SEC-007
Download PDF Contact Legal Contact Privacy

On this page

  1. 1. Purpose and Scope
  2. 2. Vendor Security Principles
  3. 3. Vendor Intake and Classification
  4. 4. Subprocessor Management
  5. 5. Ongoing Monitoring
  6. 6. Access and Offboarding
  7. 7. Partner and Marketplace Vendors
  8. 8. Customer and Enterprise Requests
  9. 9. Exceptions
  10. 10. Policy Review
  11. 11. Contact

All legal documents

Vendor Security Policy

This Vendor Security Policy ("Policy") describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") evaluates, contracts with, and oversees third-party vendors and Subprocessors that access, process, or support systems containing Customer Data or production Services infrastructure.

Capitalized terms not defined herein have the meanings set forth in the MiseCentral Legal Library Defined Terms or the applicable Agreement.

1. Purpose and Scope

1.1. Purpose. MiseCentral relies on carefully selected vendors for cloud infrastructure, communications, monitoring, payment processing, and other functions. This Policy establishes security expectations and lifecycle management for those relationships.

1.2. Scope. This Policy applies to:

(a) Subprocessors that process Personal Data on MiseCentral's behalf in connection with the Services, as listed in the DPA Subprocessor disclosure;

(b) infrastructure and platform vendors with access to production environments or encryption keys;

(c) vendors handling Confidential Information or security-sensitive MiseCentral Materials; and

(d) Professional Services subcontractors engaged by MiseCentral or Partners where they may access Customer Data under MiseCentral's direction.

1.3. Customer-Facing Transparency. Subprocessors material to Personal Data processing are disclosed to Customers through the DPA Subprocessor list and notification procedures stated therein.

2. Vendor Security Principles

2.1. Risk-Based Assessment. Vendor security review is proportionate to the vendor's access level, data sensitivity, integration depth, and substitutability.

2.2. Contractual Safeguards. Vendors with access to Customer Data or production systems must be bound by written agreements imposing confidentiality, security, data protection, incident notification, and access limitation obligations consistent with the DPA and this Policy.

2.3. Least Access. Vendors receive the minimum access necessary. Production access by vendor personnel is avoided where practicable or is time-bound and monitored.

2.4. Accountability. MiseCentral maintains an inventory of material vendors and Subprocessors with assigned internal ownership.

3. Vendor Intake and Classification

3.1. Security Questionnaire. Material vendors complete security due diligence appropriate to tier, which may include standardized questionnaires, certification review, penetration test summaries, or privacy documentation.

3.2. Tiering. MiseCentral classifies vendors by tier based on:

(a) whether the vendor processes, stores, or transmits Customer Data or Personal Data;

(b) whether the vendor has privileged access to production systems;

(c) whether outage or compromise would materially affect Service availability or data confidentiality; and

(d) regulatory or contractual requirements applicable to Customers.

3.3. Prohibition. MiseCentral does not engage vendors to process Customer Data for unrelated purposes, including model training, except as permitted in the Agreement with appropriate Customer authorization or use of Aggregated Data as defined therein.

4. Subprocessor Management

4.1. Written Agreements. Each Subprocessor is engaged under an agreement requiring implementation of appropriate technical and organizational measures, confidentiality, subprocessors restrictions where applicable, assistance with data subject requests, deletion or return of data upon termination, and security incident notification without undue delay.

4.2. Subprocessor List. MiseCentral maintains and publishes a current Subprocessor list as described in the DPA. Changes to Subprocessors follow DPA notice procedures.

4.3. Flow-Down. MiseCentral imposes data protection obligations on Subprocessors substantially similar to those MiseCentral owes Customers under the DPA.

4.4. Customer Objection. Customer objection rights to new Subprocessors, if any, are stated in the DPA.

5. Ongoing Monitoring

5.1. Periodic Reassessment. Material vendors are reassessed on a periodic schedule or upon trigger events such as ownership change, reported breach, material service change, or loss of certification.

5.2. Incident Notification. Vendors must notify MiseCentral of confirmed security incidents affecting MiseCentral data or systems without undue delay. MiseCentral evaluates downstream Customer notification obligations.

5.3. Vulnerability and Patch Management. Infrastructure vendors are expected to maintain patch and vulnerability management programs. MiseCentral tracks vendor advisories affecting the Services.

5.4. Performance and Availability. Vendors critical to Service availability are monitored for SLA performance aligned with MiseCentral's commitments in the Customer SLA.

6. Access and Offboarding

6.1. Access Provisioning. Vendor access to MiseCentral systems is provisioned individually, time-limited where possible, and logged.

6.2. Credential Management. Vendor integration credentials and API keys are rotated according to risk and stored using MiseCentral secrets management practices.

6.3. Offboarding. Upon contract termination, MiseCentral revokes vendor access, retrieves or destroys MiseCentral Confidential Information in the vendor's possession according to the agreement, and confirms data deletion or return for Subprocessors processing Personal Data.

7. Partner and Marketplace Vendors

7.1. Partners offering Connected Services, Marketplace listings, or implementation services are governed by Partner Agreements in addition to this Policy where they process data on MiseCentral's behalf.

7.2. Marketplace offerings from third parties are subject to Marketplace Participation Agreement requirements. Customers authorize integrations separately through organization controls.

7.3. MiseCentral evaluates partner security posture as part of partner program onboarding and certification where applicable.

8. Customer and Enterprise Requests

8.1. Enterprise Customers may request Subprocessor documentation, vendor security summaries, or completed questionnaires subject to the Agreement and confidentiality restrictions.

8.2. MiseCentral may decline requests for vendor audit rights that are not required by law or the Agreement, offering alternative assurance such as third-party reports where available.

9. Exceptions

9.1. Exceptions to vendor security requirements require documented risk assessment, compensating controls, and approval by MiseCentral's security function and applicable business owner.

9.2. Emergency vendor engagement for continuity may proceed with subsequent documentation and review.

10. Policy Review

10.1. This Policy is reviewed at least annually and upon material changes to vendor landscape or regulatory requirements.

11. Contact

MiseCentral LLC Attn: Security — Vendor Management 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com

Legal inquiries: legal@misecentral.com

Version history

VersionEffectiveSummary
1.0August 1, 2026Initial publication of the Legal Library (LEGAL-01).

Previous versions remain available for reference and are never overwritten.

MiseCentral

The Adaptive Operating System for Hospitality—smoother operations, adaptive intelligence, and people in command.

Product

Product Tour Platform Work Intelligence Solutions Industries Pricing

Trust

Trust Center Legal Privacy Security Status Responsible AI

Company

About Resources Support Procurement Contact Book a Demo
© MiseCentral LLC. All rights reserved. · Terms · Privacy · Cookies · Trust Center · Trademark