It closes tickets. It asks first.

SOC 2 Type II

GDPR

CCPA

SSO and SCIM

Audit log export

01

01

Mesa asks before anything risky

Mesa asks before anything risky

Every playbook is marked safe or risky when you write it. Risky actions stop and post their plan in the ticket thread, and a named person has to approve before anything moves. There is no setting that turns that off.

Every playbook is marked safe or risky when you write it. Risky actions stop and post their plan in the ticket thread, and a named person has to approve before anything moves. There is no setting that turns that off.

02

02

Scopes are the narrowest that still work

Scopes are the narrowest that still work

The Slack, Zendesk and Salesforce apps ask for the smallest set of permissions that lets a playbook run. If a playbook does not need write access, the token it uses does not have it.

The Slack, Zendesk and Salesforce apps ask for the smallest set of permissions that lets a playbook run. If a playbook does not need write access, the token it uses does not have it.

03

03

Your data stays in your tools

Your data stays in your tools

Mesa reads tickets to decide what to do and writes back the result. It does not build a copy of your helpdesk. Ticket bodies are held for ninety days for the audit log, then deleted.

Mesa reads tickets to decide what to do and writes back the result. It does not build a copy of your helpdesk. Ticket bodies are held for ninety days for the audit log, then deleted.

04

04

Nothing trains a model

Nothing trains a model

Your tickets, your playbooks and your approvals never enter a training set, ours or a vendor’s. It sits in the contract, not only on this page.

Your tickets, your playbooks and your approvals never enter a training set, ours or a vendor’s. It sits in the contract, not only on this page.

05

05

Encryption and keys

Encryption and keys

TLS 1.3 in transit, AES-256 at rest. Integration tokens live in a hardware-backed key store and are never written to a log or shown in the interface after they are saved.

TLS 1.3 in transit, AES-256 at rest. Integration tokens live in a hardware-backed key store and are never written to a log or shown in the interface after they are saved.

06

06

Every action is logged

Every action is logged

What ran, what it changed, who approved it and which ticket it touched. Exportable as CSV or streamed to your own store, kept as long as your retention says.

What ran, what it changed, who approved it and which ticket it touched. Exportable as CSV or streamed to your own store, kept as long as your retention says.

07

07

Certifications and reviews

Certifications and reviews

SOC 2 Type II, audited every year by an independent US firm. Penetration test summary and the full report go out under NDA. We answer security questionnaires in five working days.

SOC 2 Type II, audited every year by an independent US firm. Penetration test summary and the full report go out under NDA. We answer security questionnaires in five working days.

Send us the questionnaire.

security@mesa.app goes to an engineer, not to a queue. Questionnaires come back in five working days and the SOC 2 report goes out under NDA the same day you ask.

Create a free website with Framer, the website builder loved by startups, designers and agencies.