Security
Security and data handling at Mise
A plain statement of how Mise handles the data your hotel puts into it, where it runs, who can see what, and what we do not claim.
Last updated
Where Mise runs
Mise runs on Google Cloud and Firebase. Staff, managers and standards owners use Mise in a standard web browser; there is no software to install on your property network and no integration with your PMS.
Google Cloud encrypts customer content at rest by default and documents how in its default encryption at rest (opens in a new tab) guide. Traffic between browsers and Mise is served over HTTPS.
Production data is hosted in India.
What data Mise holds
Mise holds the data needed to run and evidence your standards:
- People: names, roles and the property each person works at.
- Standards: the SOPs your standards owners write, with versions, reference photos and evidence requirements.
- Execution records: task assignments, step completions, timestamps, durations against target, supervisor sign-offs and comments.
- Evidence: photos captured inside tasks at gated steps.
- Acknowledgements: who confirmed which version of a standard, with a timestamp, device label and record ID.
Mise does not need guest data, payment data or PMS access to work.
Who can see what
Mise has three role interfaces, and access follows the role:
- Staff see their own tasks, the standards assigned to them and their own service record.
- Managers see their property's live picture, team readiness, acknowledgements and results.
- Standards owners write, publish and improve standards, and read feedback on them.
Your data belongs to you
The service record is your property's record. During and after a pilot you can export it; filtered acknowledgement records already export as CSV. If you end your use of Mise, tell us and we will agree how your data is returned and deleted.
What we do not claim
Mise does not currently hold SOC 2, ISO 27001 or any other security or compliance certification, and we do not claim that Mise makes your property compliant with any regulation. When that changes, this page will say so, with evidence.
Data protection law
Our policies are written with India's Digital Personal Data Protection Act, 2023 in mind and, where they apply, the UK and EU GDPR. The privacy policy explains how we handle personal data on this website and in the platform.
Reporting a security issue
If you believe you have found a security issue in Mise or on this website, please email us with the details. We will acknowledge your report and keep you informed while we investigate. Please do not access other people's data or disrupt the service while testing.
Book a demo
Questions about how Mise handles data?
Ask us anything in a 15-minute demo, or see the platform running on a live demo property.