Security controls

Verify identity, proximity, and the server decision together.

MesaiGo does not leave security to one technology. The device, gateway, BLE/UWB, and server use complementary controls; missing or inconsistent information cannot become an access approval or attendance record.

FCDenied when a required check is missing
Single-use request
1:1One complete record per attempt
RECORDSecurity level saved with every result
Threats and controls

We explain which control addresses each risk.

MesaiGo does not claim to be “unbreakable.” Separate controls address lending an enrolled phone to someone else, reuse of an old transaction, live relay, key compromise, fake gateways, unauthorized door commands, and administrator misuse.

01

Copying a phone key

The key cannot be exported from supported secure phone storage, and iOS or Android verifies the app and key.

02

Reusing an old request

Every request expires quickly, works only once, and is permanently marked as used before the final result is returned.

03

Forwarding a live signal

High Assurance uses secure UWB distance measurement and field tests against relay and distance-reduction attacks.

04

Fake gateway

The server verifies the gateway certificate, signed settings, per-transaction gateway signature, and mTLS connection.

05

No downgrade when a required check is missing

If a check required by the entry rule is incomplete, the system does not fall back to a lower security level; it denies the transaction.

06

Administrator misuse

Job-based permissions, additional verification for critical actions, a required reason, two-person approval, and an unchangeable action history.

Keys and software updates

Keys are renewed, and devices install only signed software.

Production keys are stored in KMS/HSM systems; every device connects with its own identity; expired or compromised keys are revoked; only signed software is installed; and the device can return to the last known-good version when recovery is required.

01

Mobile keys

Phone enrollment, platform verification, transaction signing, phone replacement, and key revocation.

02

Gateway keys

Manufacturing record, hardware-protected identity, certificate, and transfer to another organization.

03

Release controls

Repeatable builds, signed software lists, gradual deployment, and return to the last known-good version.

Review MesaiGo security information in one place.

See completed security tests, product versions covered, data use, vulnerability reporting, service status, and security notices.