Skip to content
mMise

Security

Your clients trust you. You can trust where their details live.

Guest lists, VIP details, contracts and margins are some of the most sensitive things an agency holds. We built the platform so the rules are enforced by the database, not just hidden on screen.

Every agency is sealed off

Each record carries the agency it belongs to, and the database itself checks every read and write against your membership. Another agency can't see your work, even by mistake in our code.

Money is private by role

Only owners, producers and finance see costs, fees and margin. Money is stored in separate tables that other roles can't read, so coordinators and freelancers never download it at all.

Private links for clients and partners

Clients and partners get a link per event, not an account. Each link holds a long random key, we only store a fingerprint of it, and you can switch it off at any time.

Clients see only what you share

The client portal shows readiness, decisions, shared reports and the run of show. Never costs, fees, line items, internal notes, hidden workstreams or other events.

Files stay private

Contracts, quotes and designs live in private storage, limited to your agency. Each file opens through a link that expires after 60 seconds.

Offline, without leaving a trace

Event-day mode keeps working without signal, and leaves money out of the offline copy. Signing out deletes everything stored on the device.

AI that respects the same rules

Mise AI runs on our servers and only reads what the person asking is allowed to see. It never discusses money with roles that can't see costs.

Keys never reach the browser

Service keys and API secrets stay on the server. Connections are encrypted in transit, and passwords are handled by our authentication provider, never stored by us.

For your IT team

The details

A plain summary of how the platform is built. We're happy to walk your team or your client's security team through any of it.

Hosted on Vercel and Supabase. Data is encrypted in transit with TLS.
Tenant isolation
Postgres row-level security on every business table, tested automatically against the real database.
Roles
Owner, producer, finance, coordinator and freelancer. Only the first three can see costs.
Portal links
192-bit random tokens, stored as SHA-256 hashes, revocable, and every portal action re-checks the link.
Portal pages
Sent with no-index and no-referrer, so links don't leak to search engines or other sites.
File access
Private buckets limited to your agency. Files open through signed URLs that expire after 60 seconds.
Partner uploads
One-time signed upload links into a folder for that partner only, checked on the server before they're saved.
Live updates
Private realtime channels, authorised per agency, with a separate channel for cost roles.
Offline data
Stored per person and per agency, without money, and deleted on sign-out.
AI
Context is built on the server from your own permissions. Each agency has a daily allowance.

Found something?

If you think you've found a security problem, please email liyusoftwaresolutions@gmail.com with “Security” in the subject, or call or message +251 92 321 4663. We'll reply quickly and keep you updated until it's fixed.

Questions from your client's security team?

Book a walkthrough and bring them along. We'll show them exactly what a client, a partner and each role can see.

Follow Mise on Product Hunt