Physical proximity evidence platform

Prove that the right device is actually there.

MesaiGo turns a live interaction between an employee-bound trusted device and an authorized gateway into an auditable result using device identity, a fresh challenge, BLE or secure UWB proximity evidence, and a server-authoritative decision.

Explore the security model
MesaiGo device, gateway, UWB, server, and audit evidence flow
LIVE EVIDENCE SESSION HIGH ASSURANCE · UWB
01 TRUSTED ENDPOINT Device-bound identity VERIFIED
02 PHYSICAL EVIDENCE Secure UWB ranging 0.82 m
03 FIELD WITNESS Authorized gateway witness SEALED
04 DECISION AUTHORITY Policy and replay control ACCEPTED
EVIDENCE RECEIPT · 7F2A HIGH ASSURANCE ACCEPTED
Device-bound Mobile identity
Live interaction BLE + UWB
Decision authority Server
Default behavior Fail-closed
Outcome Auditable evidence
Evidence before records

Location can be a claim. Evidence requires a live chain.

GPS coordinates can be altered, QR codes can be shared, and cards can be handed over. Instead of trusting a single user input, MesaiGo combines device, gateway, freshness, proximity, and policy evidence in the same transaction.

01

Recognizes the phone

The credential can be used only inside the secure key boundary of the enrolled device.

02

Recognizes the point

The gateway binding to the organization and entry point is verified by the server authority.

03

Recognizes the moment

A fresh challenge and single-use evidence prevent an old transaction from being replayed.

04

Recognizes the assurance

A Standard or High Assurance result is produced only when the required evidence is actually present.

Evidence Explorer

See how a decision becomes evidence, step by step.

Choose an assurance profile and product outcome. MesaiGo shows which trust boundary is active at every step and which policy produced the result.

Standard

A live interaction with an authenticated BLE gateway.

  1. 01

    Device-bound identity

    A non-exportable mobile credential is verified in the context of the employee and organization.

  2. 02

    Correct gateway

    The app selects the relevant entry point and gateway identity, not simply the strongest signal.

  3. 03

    Fresh challenge

    The gateway creates a time-bound, single-use transaction context for every attempt.

  4. 04

    Mobile evidence

    The device signs the attempt, entry point, purpose, and challenge bindings in a standardized form.

  5. 05

    Gateway witness

    The gateway seals the evidence it observed with its own key and submits it to the decision authority.

  6. 06

    Server decision

    Identity, freshness, assignment, policy, and replay checks converge in one decision.

  7. 07

    Audit receipt

    The result, assurance level, and policy version are written to the immutable event chain.

High Assurance

Local user approval and secure UWB ranging for every transaction.

  1. 01

    Device-bound identity

    A non-exportable mobile credential is verified in the context of the employee and organization.

  2. 02

    Correct gateway

    The app selects the relevant entry point and gateway identity, not simply the strongest signal.

  3. 03

    Fresh challenge

    The gateway creates a time-bound, single-use transaction context for every attempt.

  4. 04

    Transaction approval

    The user approves every critical attempt locally with the device PIN or biometrics; biometric data never reaches MesaiGo.

  5. 05

    Secure UWB ranging

    The secure ranging session binds distance evidence to the corresponding attempt, device, gateway, and entry point.

  6. 06

    Mobile evidence

    The device signs the attempt, entry point, purpose, and challenge bindings in a standardized form.

  7. 07

    Gateway witness

    The gateway seals the evidence it observed with its own key and submits it to the decision authority.

  8. 08

    Server decision

    Identity, freshness, assignment, policy, and replay checks converge in one decision.

  9. 09

    Audit receipt

    The result, assurance level, and policy version are written to the immutable event chain.

MESAIGO / EVIDENCE RECEIPT 7F2A-9C18

Authorized decision, signed actuation, observed passage.

  • Assurance STANDARD
  • Policy Office entry v12
  • Decision ALLOW
  • Passage OBSERVED
Sealed by the server authority
MESAIGO / EVIDENCE RECEIPT 7F2A-9C18

Verified presence, the correct shift, and transparent time records.

  • Assurance STANDARD
  • Policy Shift start v8
  • Event CLOCK_IN
  • Audit SEALED
Sealed by the server authority

Two assurance profiles

Not every door carries the same risk. Not every decision should require the same evidence.

Standard

Live BLE evidence

Balances speed with strong device-to-gateway evidence for offices, factories, and everyday attendance workflows.

  • Device-bound credential
  • Fresh, single-use challenge
  • Mobile evidence + gateway witness
  • Server-authoritative decision
Explore Standard
High Assurance

Secure UWB + transaction approval

Combines distance evidence and user approval in one decision for vaults, server rooms, and critical spaces.

  • Secure UWB ranging
  • PIN or biometrics for every attempt
  • No silent assurance downgrade
  • Physical acceptance tests against relay and distance-reduction attacks
Explore High Assurance

Compare assurance profiles by threat model, hardware, and user experience.

Scroll horizontally for the High Assurance column →
Compare assurance profiles by threat model, hardware, and user experience.
Decision criterion Standard High Assurance
Proximity evidence Live BLE transaction evidence Secure UWB distance evidence
Boundary it does not prove Does not claim cryptographically exact distance Does not grant access on its own
User verification Can be added by policy Mandatory local approval for every attempt
Required gateway Verify, Access Lite, Access, or Access Pro Access Pro and a supported UWB device
Assurance downgrade Defined Standard policy outcome Never silently falls back to Standard when evidence is missing
Audit outcome Identity, freshness, witness, policy, and result Standard chain plus ranging transcript and local approval
One evidence core, two outcomes

The same evidence core. Two independent product decisions.

An access approval does not automatically start attendance, and an attendance event does not automatically unlock a door. MesaiGo evaluates shared evidence through two separate policy engines.

MesaiGo Access

See every link from decision to physical passage.

Identity, proximity, policy, actuation, and physical passage evidence are audited separately across doors, turnstiles, private rooms, and controlled spaces.

  • Policy- and assurance-based authorization
  • Signed, single-use unlock command
  • Door contact, tamper, and anti-passback
  • Offline operation and emergency matrix
Explore MesaiGo Access
MesaiGo Attendance

Turn verified presence into payroll-ready time.

Shifts, breaks, missing departures, leave, corrections, and approvals are managed without rewriting the underlying evidence.

  • Time records from arrival and departure events
  • Shifts, overnight work, and overtime
  • Employee self-service and disputes
  • Payroll/ERP export with an immutable audit trail
Explore MesaiGo Attendance
System anatomy

Trust is created by a bounded system, not a single device.

The phone does not approve itself. The gateway cannot unlock a door by itself. The management panel does not make security decisions. Each component carries only its own evidence.

Explore the technical flow
  1. 01
    Mobile deviceIdentity + local approval
  2. 02
    GatewayChallenge + witness
  3. 03
    UWB zoneSecure distance evidence
  4. 04
    Decision authorityPolicy + replay control + assurance
  5. 05
    Controller / actuatorSigned command + physical outcome
  6. 06
    Access / AttendanceSeparate product outcomes
  7. 07
    Management and integrationsScoped authority + versioned API
  8. 08
    AuditExplainable and reviewable
MesaiGo Gateway

A hardware family that scales to the site without compromising security.

From WiFi + BLE verification to Ethernet, NFC, field I/O, and secure UWB, every model follows the same identity, policy, OTA, and audit discipline.

VerifyWiFi · BLEAttendance and physical presence
Access LiteWiFi · BLE · 2R/4IDoors and turnstiles
AccessEthernet · WiFi · BLE · NFCEnterprise access
Access ProEthernet · WiFi · BLE · NFC · UWBHigh Assurance
Compare the gateway family
A hardware family that scales to the site without compromising security.
LIVE EVIDENCE
BLEFresh challengeGateway witness
HIGH ASSURANCE
Secure UWBLocal transaction approval
FIELD CONTROL
2 relays4 protected inputsNFC
LIFECYCLE
Signed OTAFleet healthFail-closed
One center, explainable operations

One operational discipline from policy to device health, event to payroll.

MesaiGo management screens are not decoration; they are where operators work with decisions and the resulting audit trail. The values below represent an illustrative business scenario that explains the product flow.

DECISION / 7F2A

Live decision stream

Review allow, deny, constrained-operation, and anomaly events with assurance and policy context.

FLEET / HEALTHY

Gateway fleet health

Manage identity, firmware, connectivity, tamper, UWB calibration, and rollout status.

EXCEPTIONS / 12

Attendance exceptions

Resolve missing departures, breaks, overtime, and correction requests without changing the raw evidence.

POLICY / EXPLAINED

Authorization visibility

Explain who can do what, for which organization, facility, entry point, and time scope.

Explore the management platform
Enterprise ecosystem

Documented data flows from identity to payroll, controllers to SIEM.

MesaiGo integrations do more than display logos. Each one documents what it reads and writes, its authentication method, failure model, ownership, and version contract.

MESAIGOVERSIONED CONTRACTS
01

Identity

SAML · OIDC · SCIM

02

HR and payroll

HRIS · ERP · Payroll

03

Physical systems

OSDP SC · I/O · Fire

04

Security

SIEM · Signed webhook

05

Developer

API · Sandbox · Changelog

06

Deployment

Cloud · Cell boundary

Explore integration contracts
Privacy in the architecture

Verify presence without tracking people.

MesaiGo does not base access or attendance decisions on GPS coordinates and does not collect face images, fingerprints, or biometric templates. High Assurance user verification remains inside the device operating system.

  • No background GPS tracking
  • No centralized biometric templates
  • Purpose- and time-limited evidence
  • Employee visibility and correction trail
Explore the privacy approach
MesaiGo Mobile

Strong evidence in a focused, seconds-long experience.

From enrollment to verification, employees do not see the underlying technical complexity. They choose the correct space, approve the transaction on-device when required, and see the server-signed result.

Explore the mobile app
MesaiGo mobile app High Assurance result screen
01
VERIFICATION FLOW Bind the device securely
VERIFIED
02
VERIFICATION FLOW Open the correct entry point
VERIFIED
03
VERIFICATION FLOW Verify with Standard or High Assurance
VERIFIED
04
VERIFICATION FLOW View the result and your own attendance record
VERIFIED
High Assurance · Access Pro Access verified SEALED
Mobile distribution

MesaiGo Mobile for iPhone and Android under one security contract.

Store listings are published with the exact build, privacy disclosure, support link, and compatibility matrix. Review teams receive a version-bound, time-limited package that is clearly identified as a simulation and requires no physical hardware.

  • Device-bound credential
  • BLE Standard + UWB High Assurance
  • Version-bound review simulation
  • Clear privacy and permissions

Store badges appear only after verified product-page URLs are bound to the release configuration.

MESAI GO MOBILE Evidence, on your device. iPhone · Android
Explore the mobile product and review flow
Trust Center

Instead of saying “trust us,” we show what each decision relies on.

01

Threat model

Sharing, replay, live relay, assurance downgrade, key compromise, and physical field risks are modeled explicitly.

02

Device lifecycle

Enrollment, verification, key rotation, revocation, device replacement, and secure preparation are managed as one lifecycle.

03

Security operations

SBOM, signed releases, responsible disclosure, security advisories, service status, and incident-response surfaces are provided.

04

Privacy governance

Data purpose, retention, employee access, and legal assessment are managed in a traceable form.

Explore the Trust Center
Architecture assessment

Let us discuss the evidence you need, not just your door or attendance process.

We will evaluate your entry points, risk level, employee experience, and existing infrastructure to identify the right assurance and gateway profile.