Copying a phone key
The key cannot be exported from supported secure phone storage, and iOS or Android verifies the app and key.
MesaiGo does not leave security to one technology. The device, gateway, BLE/UWB, and server use complementary controls; missing or inconsistent information cannot become an access approval or attendance record.
MesaiGo does not claim to be “unbreakable.” Separate controls address lending an enrolled phone to someone else, reuse of an old transaction, live relay, key compromise, fake gateways, unauthorized door commands, and administrator misuse.
The key cannot be exported from supported secure phone storage, and iOS or Android verifies the app and key.
Every request expires quickly, works only once, and is permanently marked as used before the final result is returned.
High Assurance uses secure UWB distance measurement and field tests against relay and distance-reduction attacks.
The server verifies the gateway certificate, signed settings, per-transaction gateway signature, and mTLS connection.
If a check required by the entry rule is incomplete, the system does not fall back to a lower security level; it denies the transaction.
Job-based permissions, additional verification for critical actions, a required reason, two-person approval, and an unchangeable action history.
Production keys are stored in KMS/HSM systems; every device connects with its own identity; expired or compromised keys are revoked; only signed software is installed; and the device can return to the last known-good version when recovery is required.
Phone enrollment, platform verification, transaction signing, phone replacement, and key revocation.
Manufacturing record, hardware-protected identity, certificate, and transfer to another organization.
Repeatable builds, signed software lists, gradual deployment, and return to the last known-good version.
See completed security tests, product versions covered, data use, vulnerability reporting, service status, and security notices.