Security
Last updated October 9, 2026
Restaurants trust MISE EN AI with financial and operational data. We use administrative, technical and organizational safeguards designed to protect it. This page summarizes them. No system is completely secure, and we can’t guarantee that information will never be accessed, disclosed, altered or lost.
Encrypted connections
MISE EN AI is served only over HTTPS, and browsers are told to always use HTTPS for it. The application calls the providers it uses over HTTPS.
Sign-in and sessions
- Passwords are stored only as salted one-way hashes, never in readable form.
- Two-step login with an authenticator app is available to every user, with one-time recovery codes, and an organization can require it for all its members.
- Sign-in attempts and password-reset requests are rate limited, and sign-in errors don’t reveal whether an account exists.
- Session cookies can’t be read by page scripts. Sessions expire after inactivity and after a maximum age, which an organization can shorten. Users can see where they are signed in and sign out other devices; changing a password signs out other sessions.
- Email links for confirmation and password reset are single-use and short-lived.
Access control and tenant separation
- Each organization’s data is separated in the database by access rules that are enforced on every query, in addition to permission checks in the application.
- Role-based permissions, including custom roles, decide what each person can see and do, and can be limited to particular brands or locations. Individual wage information requires its own payroll permission.
- API keys carry only the permissions their creator chooses (never more than the creator has), can expire, can be revoked, and are rate limited.
Protecting sensitive data
- Access tokens for connected services, two-step login secrets and notification webhook addresses are encrypted by the application before they are stored, and are never shown back.
- Uploaded document originals are encrypted by the application before they are placed in file storage, and are reached only through the application’s permission checks.
- Bank connections go through Plaid: bank credentials are entered in Plaid’s window and never reach us, and we store only the last four digits of an account number.
- Payment card details are entered on Stripe’s pages. We never receive or store full card numbers.
- Logs and audit records are designed to exclude passwords, tokens and secrets.
Audit trail
Important actions in an organization, such as changes to costs, prices, roles, integrations and approvals, are recorded in an audit log that can’t be edited or deleted through the application. Organizations can review it in the Service.
Application safeguards
- Inputs are validated, database queries are parameterized, and the site sends security headers, including a content security policy, that limit what pages can load and that refuse framing by other sites.
- Uploaded files are checked by their content, not their name; unsupported types and PDFs with active content are refused; and originals are served back only to authorized users with restrictive headers.
- Incoming webhooks from providers such as Stripe, Square and Plaid are accepted only with a valid signature.
- Rate limits apply to sign-in, password resets, the AI CFO, the public API and other sensitive operations.
AI safeguards
AI models reach data only through narrow functions that check the asking user’s permissions, and never have direct database access. Uploaded documents are treated as untrusted, so instructions hidden in a document can’t direct the system. AI output is checked and shown for review: invoices wait for a person before they change costs, and proposed actions change nothing until someone with permission approves them. See our privacy policy for what AI providers receive.
Operations
- The application runs on managed serverless infrastructure in the United States, with a managed database. See our subprocessors.
- Administrative access to production systems is limited to authorized personnel, through accounts that require two-step login. Secrets are kept in the hosting platform’s secret storage, not in source code.
- Customer data is viewed by our personnel only when needed to provide support the customer asked for, to secure the Service, or to meet legal obligations.
- Every change runs automated type checks and tests before release, and dependencies are reviewed for known vulnerabilities.
- We maintain an incident response process covering containment, investigation, notice to affected customers as required by law and our agreements, and follow-up.
Your part
Security is shared. Turn on two-step login (and require it for your organization), give each person their own login with only the permissions they need, remove access when someone leaves, keep API keys secret, and review the audit log.
Report a vulnerability
If you believe you have found a security issue in MISE EN AI, email williamsedgwick@miseenai.com with the details. Please give us a reasonable chance to fix it before sharing it, and don’t access other people’s data, disrupt the Service or run automated scans against it.