MesaiGo Gateway

The same security core. Four hardware profiles for the field.

Every gateway is managed by product, hardware profile, firmware target, and capability identity. A device cannot claim a capability it does not have or receive firmware for a different target.

Gateway capability architecture
LOCAL RADIO
BLENFCSecure UWB
FIELD INTERFACE
2 relays4 protected inputsTamper detection
CONNECTIVITY
EthernetWiFi backupmTLS
SECURITY
Hardware identitySigned OTAFail-closed
Product family

Only the hardware you need. The same security discipline in every model.

Capability, hardware profile, and firmware target remain distinct. Each device carries only physically present and accepted capabilities.

01

Gateway Verify

gateway_lite_verify

A compact WiFi + BLE gateway for attendance and physical-presence verification points.

Uplink
WiFi
Local communication
BLE
Access I/O
Verification-focused
Assurance
Standard
Suitable spaces
Office, factory, and attendance point
Evaluate this model
02

Gateway Access Lite

gateway_lite_access

Connects existing door and turnstile infrastructure with secure actuation and sensor evidence.

Uplink
WiFi
Local communication
BLE
Access I/O
2 relays + 4 protected inputs
Assurance
Standard
Suitable spaces
Door, turnstile, and controlled space
Evaluate this model
03

Gateway Access

gateway_standard_access

An enterprise access point with primary Ethernet, backup WiFi, BLE, and NFC.

Uplink
Ethernet + backup WiFi
Local communication
BLE + NFC
Access I/O
2 relays + 4 protected inputs
Assurance
Standard + additional verification
Suitable spaces
Enterprise building and multiple entry points
Evaluate this model
Shared security core

Core security principles are preserved in every model.

Identity, server authority, signed configuration, target-bound OTA, secret-free audit trails, and fail-closed behavior are consistent across the product family. The available assurance level is explicitly separated by each model’s accepted physical capabilities.

01

Hardware-bound identity

Secure production provisioning, non-exportable device keys, key rotation, and revocation.

02

Target-scoped OTA

Signed manifest, correct firmware target, anti-rollback, boot verification, and safe recovery.

03

Protected field I/O

Relay, door contact, REX, tamper, turnstile direction, and fault classes.

04

Fail-closed actuation

No unintended pulse during boot, reset, brownout, network uncertainty, or policy uncertainty.

05

Secure commissioning

Correct cell/organization binding, capability acceptance, and signed configuration.

06

Fleet observability

Network, firmware, key, tamper, sensor, calibration, and health telemetry.

Choose the right gateway profile for your site.

Let us evaluate network, I/O, assurance, UWB, and lifecycle requirements together.