Security by architecture

Build security on mutually verifying boundaries, not one technology.

BLE, UWB, a secure hardware boundary, or the server alone is not the product’s security claim. MesaiGo makes attacks across layers visible and auditable.

FCFail-closed by default
Replay consumption
E2EBound transaction transcript
AUDITExplicit assurance level
Threat → control → evidence

Every claim states which threat it reduces and by which control.

MesaiGo does not use absolute “unbreakable” language. Credential sharing, replay, live relay, assurance downgrade, key compromise, fake gateways, unauthorized actuation, and administrator misuse are distinct threats.

01

Credential cloning

Hardware-backed, non-exportable keys and platform attestation.

02

Replay

Fresh challenge, durable consumption record, idempotency control, and binding to the final result.

03

Live relay

Secure UWB ranging, bound transaction transcript, and physical acceptance tests in High Assurance.

04

Fake gateway

Gateway identity, signed configuration, witness HMAC, mTLS, and an authenticated final result.

05

Silent assurance downgrade

Entry policy and capability acceptance with fail-closed behavior when evidence is missing.

06

Administrator misuse

Scope-aware RBAC, step-up verification, justification, dual control, and an immutable audit trail.

Key and release lifecycle

Keys and firmware are part of the product lifecycle.

KMS/HSM key custody, production identity, per-device mTLS, key rotation and revocation, signed OTA, SBOM, anti-rollback, and recovery are governed by the same security contract.

01

Mobile identity

Device enrollment, attestation, transaction key, device replacement, and revocation.

02

Gateway identity

Production provenance, hardware root of trust, certificate, and ownership transfer.

03

Release custody

Reproducible output, signed manifest, staged rollout, and rollback.

Review security evidence in one place.

Testing scope, privacy, vulnerability reporting, service status, and advisories.