It closes tickets. It asks first.
SOC 2 Type II
GDPR
CCPA
SSO and SCIM
Audit log export
01
01
Mesa asks before anything risky
Mesa asks before anything risky
Every playbook is marked safe or risky when you write it. Risky actions stop and post their plan in the ticket thread, and a named person has to approve before anything moves. There is no setting that turns that off.
Every playbook is marked safe or risky when you write it. Risky actions stop and post their plan in the ticket thread, and a named person has to approve before anything moves. There is no setting that turns that off.
02
02
Scopes are the narrowest that still work
Scopes are the narrowest that still work
The Slack, Zendesk and Salesforce apps ask for the smallest set of permissions that lets a playbook run. If a playbook does not need write access, the token it uses does not have it.
The Slack, Zendesk and Salesforce apps ask for the smallest set of permissions that lets a playbook run. If a playbook does not need write access, the token it uses does not have it.
03
03
Your data stays in your tools
Your data stays in your tools
Mesa reads tickets to decide what to do and writes back the result. It does not build a copy of your helpdesk. Ticket bodies are held for ninety days for the audit log, then deleted.
Mesa reads tickets to decide what to do and writes back the result. It does not build a copy of your helpdesk. Ticket bodies are held for ninety days for the audit log, then deleted.
04
04
Nothing trains a model
Nothing trains a model
Your tickets, your playbooks and your approvals never enter a training set, ours or a vendor’s. It sits in the contract, not only on this page.
Your tickets, your playbooks and your approvals never enter a training set, ours or a vendor’s. It sits in the contract, not only on this page.
05
05
Encryption and keys
Encryption and keys
TLS 1.3 in transit, AES-256 at rest. Integration tokens live in a hardware-backed key store and are never written to a log or shown in the interface after they are saved.
TLS 1.3 in transit, AES-256 at rest. Integration tokens live in a hardware-backed key store and are never written to a log or shown in the interface after they are saved.
06
06
Every action is logged
Every action is logged
What ran, what it changed, who approved it and which ticket it touched. Exportable as CSV or streamed to your own store, kept as long as your retention says.
What ran, what it changed, who approved it and which ticket it touched. Exportable as CSV or streamed to your own store, kept as long as your retention says.
07
07
Certifications and reviews
Certifications and reviews
SOC 2 Type II, audited every year by an independent US firm. Penetration test summary and the full report go out under NDA. We answer security questionnaires in five working days.
SOC 2 Type II, audited every year by an independent US firm. Penetration test summary and the full report go out under NDA. We answer security questionnaires in five working days.
Send us the questionnaire.
security@mesa.app goes to an engineer, not to a queue. Questionnaires come back in five working days and the SOC 2 report goes out under NDA the same day you ask.