Pricing
Some controls described below are marked Planned and are being implemented ahead of general availability.

Security Policy

Last updated: September 1, 2026

Mise handles sensitive restaurant data — invoices, payment details, business contacts, and figures that can include employee names and salaries. This page describes how we protect that data. Where a control is still being rolled out ahead of general availability, it is marked Planned.

1. Encryption

  • All traffic is encrypted in transit with TLS 1.2+; HTTPS is enforced everywhere.
  • Data is encrypted at rest with AES-256 by our cloud provider.
  • Application secrets are held in a managed secret store and encrypted with our own keys in Google Cloud KMS, on top of the provider’s at-rest encryption.
  • Broader field-level encryption for other sensitive columns. Planned

2. Infrastructure

Mise runs on Google Cloud / Firebase, a major cloud platform that maintains its own independent security certifications. We use managed services to reduce our patching and configuration surface. Mise itself does not currently hold a formal security certification.

3. Access control & authentication

  • Sign-in is via Google OAuth. We never see or store user passwords.
  • Role-based access control governs every action; access is granted on a least-privilege basis.
  • Platform (operator) access is separated from restaurant access, scoped through groups, and recorded.
  • Sign-in is delegated to Google, so multi-factor authentication is enforced by your Google account policy. App-enforced MFA for administrative access. Planned

4. Tenant isolation

Each restaurant’s data is logically segregated, and access is enforced server-side by security rules that are designed so one tenant cannot read another’s data. Platform operators only see the restaurants their role and groups permit.

5. Payment security

Mise takes no payments today: the Service is free during beta, and we hold no card details of any kind. When payments begin, they will be handled by Stripe, certified to PCI-DSS Level 1, and Mise will never store full card numbers. Planned See §8.

6. Where your documents live

Mise is zero-copy by design for the documents you capture. Invoice and recipe images and PDFs are written into your own Google Drive, under a single root folder you choose; Mise keeps only the file identifiers and the structured data extracted from them. We hold the narrow drive.file permission (what that scope covers), which covers only the files the app creates or that you explicitly open with it. The refresh token behind that access is encrypted with our own KMS keys (§1), and you can revoke it from Settings at any time. The practical effect: the largest and most sensitive body of your content never accumulates in our systems at all.

7. AI & data minimization

Documents sent for AI processing are transmitted over encrypted channels, used only to return a result, and not used to train models. AI usage can be disabled per restaurant. See §5.

8. Application security

  • All input is validated server-side, and every read and write is checked against server-enforced database security rules — the client cannot reach data its rules do not permit. Those rules are covered by an automated test suite that runs before each deploy.
  • Dependencies are monitored for known vulnerabilities, and each change passes an automated gate — type checks, tests, security-rules tests, dependency audit, and secret scanning — before it can ship.
  • Response security headers — X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, Strict-Transport-Security, and an enforced Content-Security-Policy — are applied on every response.

9. Logging & monitoring

Administrative and security-relevant actions are written to a tamper-evident audit stream that only our servers can append to — there is no path for a browser to write or alter it. We avoid logging personal data and mask identifiers where logging is necessary.

10. Backups & resilience

The database has continuous point-in-time recovery, plus scheduled daily and weekly backups, and the site itself can be rolled back to a previous release. Restore drills against an isolated copy — never against production — on a recurring schedule. Planned Your captured documents live in your own Google Drive (§6) and are covered by Google’s protections for your account rather than ours.

11. Vulnerability disclosure

We welcome responsible disclosure. Email security@everydaymise.com with details and steps to reproduce. Please give us reasonable time to remediate before any public disclosure; we will not pursue good-faith researchers.

12. Incident response

We maintain a written incident-response plan with a named owner, defined severity tiers, and set response times, covering containment, investigation, and customer and regulator notification. If we become aware of a security incident affecting your data, we investigate promptly and notify affected customers where appropriate. Report a suspected incident to security@everydaymise.com.

13. Sub-processor management

Sub-processors are vetted and tracked in a maintained inventory, each operating under its own published data-protection terms; the inventory is re-reviewed on a recurring schedule and any new external service is added before it handles customer data. If your business requires a data-processing agreement in place before you proceed, contact us. See the (§6) for the current list.

14. Personnel security

Access to systems and customer data is limited to authorized personnel strictly on a need-to-know basis, under confidentiality obligations.

15. Data practices

  • Mise takes no payments and holds no card details today (§5). When payments begin they will be handled by Stripe, and Mise will never store card numbers or CVVs. Planned
  • We do not sell personal information, or share it with third parties for advertising or marketing purposes.

16. Data deletion & portability

Requests relating to your data are handled as described in the .

17. Contact

Naki, LLC d/b/a Everyday Mise. Security questions and reports: security@everydaymise.com. See also our and .

Everyday Mise · Restaurant Cost Intelligence
© 2026 Naki, LLC. Everyday Mise is a trade name of Naki, LLC.
PricingGuidessecurity@everydaymise.com