Recognizes the phone
The credential can be used only inside the secure key boundary of the enrolled device.
MesaiGo turns a live interaction between an employee-bound trusted device and an authorized gateway into an auditable result using device identity, a fresh challenge, BLE or secure UWB proximity evidence, and a server-authoritative decision.
Explore the security modelGPS coordinates can be altered, QR codes can be shared, and cards can be handed over. Instead of trusting a single user input, MesaiGo combines device, gateway, freshness, proximity, and policy evidence in the same transaction.
The credential can be used only inside the secure key boundary of the enrolled device.
The gateway binding to the organization and entry point is verified by the server authority.
A fresh challenge and single-use evidence prevent an old transaction from being replayed.
A Standard or High Assurance result is produced only when the required evidence is actually present.
Choose an assurance profile and product outcome. MesaiGo shows which trust boundary is active at every step and which policy produced the result.
A live interaction with an authenticated BLE gateway.
A non-exportable mobile credential is verified in the context of the employee and organization.
The app selects the relevant entry point and gateway identity, not simply the strongest signal.
The gateway creates a time-bound, single-use transaction context for every attempt.
The device signs the attempt, entry point, purpose, and challenge bindings in a standardized form.
The gateway seals the evidence it observed with its own key and submits it to the decision authority.
Identity, freshness, assignment, policy, and replay checks converge in one decision.
The result, assurance level, and policy version are written to the immutable event chain.
Local user approval and secure UWB ranging for every transaction.
A non-exportable mobile credential is verified in the context of the employee and organization.
The app selects the relevant entry point and gateway identity, not simply the strongest signal.
The gateway creates a time-bound, single-use transaction context for every attempt.
The user approves every critical attempt locally with the device PIN or biometrics; biometric data never reaches MesaiGo.
The secure ranging session binds distance evidence to the corresponding attempt, device, gateway, and entry point.
The device signs the attempt, entry point, purpose, and challenge bindings in a standardized form.
The gateway seals the evidence it observed with its own key and submits it to the decision authority.
Identity, freshness, assignment, policy, and replay checks converge in one decision.
The result, assurance level, and policy version are written to the immutable event chain.
Balances speed with strong device-to-gateway evidence for offices, factories, and everyday attendance workflows.
Combines distance evidence and user approval in one decision for vaults, server rooms, and critical spaces.
Compare assurance profiles by threat model, hardware, and user experience.
Scroll horizontally for the High Assurance column →| Decision criterion | Standard | High Assurance |
|---|---|---|
| Proximity evidence | Live BLE transaction evidence | Secure UWB distance evidence |
| Boundary it does not prove | Does not claim cryptographically exact distance | Does not grant access on its own |
| User verification | Can be added by policy | Mandatory local approval for every attempt |
| Required gateway | Verify, Access Lite, Access, or Access Pro | Access Pro and a supported UWB device |
| Assurance downgrade | Defined Standard policy outcome | Never silently falls back to Standard when evidence is missing |
| Audit outcome | Identity, freshness, witness, policy, and result | Standard chain plus ranging transcript and local approval |
An access approval does not automatically start attendance, and an attendance event does not automatically unlock a door. MesaiGo evaluates shared evidence through two separate policy engines.
Identity, proximity, policy, actuation, and physical passage evidence are audited separately across doors, turnstiles, private rooms, and controlled spaces.
Shifts, breaks, missing departures, leave, corrections, and approvals are managed without rewriting the underlying evidence.
The phone does not approve itself. The gateway cannot unlock a door by itself. The management panel does not make security decisions. Each component carries only its own evidence.
From WiFi + BLE verification to Ethernet, NFC, field I/O, and secure UWB, every model follows the same identity, policy, OTA, and audit discipline.
MesaiGo management screens are not decoration; they are where operators work with decisions and the resulting audit trail. The values below represent an illustrative business scenario that explains the product flow.
Review allow, deny, constrained-operation, and anomaly events with assurance and policy context.
Manage identity, firmware, connectivity, tamper, UWB calibration, and rollout status.
Resolve missing departures, breaks, overtime, and correction requests without changing the raw evidence.
Explain who can do what, for which organization, facility, entry point, and time scope.
MesaiGo integrations do more than display logos. Each one documents what it reads and writes, its authentication method, failure model, ownership, and version contract.
SAML · OIDC · SCIM
HRIS · ERP · Payroll
OSDP SC · I/O · Fire
SIEM · Signed webhook
API · Sandbox · Changelog
Cloud · Cell boundary
MesaiGo does not base access or attendance decisions on GPS coordinates and does not collect face images, fingerprints, or biometric templates. High Assurance user verification remains inside the device operating system.
From enrollment to verification, employees do not see the underlying technical complexity. They choose the correct space, approve the transaction on-device when required, and see the server-signed result.
Store listings are published with the exact build, privacy disclosure, support link, and compatibility matrix. Review teams receive a version-bound, time-limited package that is clearly identified as a simulation and requires no physical hardware.
Store badges appear only after verified product-page URLs are bound to the release configuration.
Sharing, replay, live relay, assurance downgrade, key compromise, and physical field risks are modeled explicitly.
Enrollment, verification, key rotation, revocation, device replacement, and secure preparation are managed as one lifecycle.
SBOM, signed releases, responsible disclosure, security advisories, service status, and incident-response surfaces are provided.
Data purpose, retention, employee access, and legal assessment are managed in a traceable form.
We will evaluate your entry points, risk level, employee experience, and existing infrastructure to identify the right assurance and gateway profile.