Access control
MizUp holds sensitive information: salaries, customer lists, invoices, student records. The first line of defence is making sure each person can only reach what their job needs.
- Role-based permissions across every module, so a manager sees their team and nothing more.
- Every record is scoped to your organisation and queries are organisation-scoped throughout. No data is shared between companies on the platform.
- Login throttling and managed sessions.
- The workspace owner decides which products and modules each person can use.
Data protection
- Integration credentials, including API keys, tokens, SMTP passwords and webhook secrets, are encrypted at rest and masked in the interface. They are never rendered back to a browser.
- Public invoice links are signed and unguessable, and are excluded from search engines.
- Outbound webhooks are signed with HMAC-SHA256 so your receiver can verify the request came from us.
- Web push messages sent from MizUp CLM are encrypted end to end between our server and the visitor's browser, as the web push standard requires.
Web and session security
- All traffic is served over HTTPS, and browsers are told to use HTTPS only through HSTS.
- Every form that changes data is protected with a per-session token against cross-site request forgery.
- Session cookies are HTTP-only and restricted to same-site use, and session identifiers are rotated periodically.
- Security headers limit framing by other sites and content-type sniffing.
Payments and messaging
- Subscription payments are processed by a PCI DSS compliant payment gateway. Card numbers are entered on the gateway's pages and are not stored by MizUp.
- When your business collects payments through MizUp Finance or MizUp CLM, you connect your own gateway account and its keys are stored encrypted.
- WhatsApp messages are sent through the official WhatsApp Business Platform using the provider you connect, and message templates follow Meta's approval process.
Data ownership and export
- Your business data belongs to you. You can export it while your account is active.
- Deleting a record in the product usually deactivates it so history and audit trails stay intact. Full deletion of an organisation's data can be requested through our privacy team.
- The same permissions apply whether your team works on the web or on the MizUp mobile apps, because access is checked on our servers, not in the app.
Accountability
- An immutable audit log records who changed what and when.
- Inbound webhooks are logged with their signature-verification result.
Your part
- Give each person their own login and remove access promptly when someone leaves.
- Grant the smallest role that lets a person do their work.
- Use a strong, unique password and never share it.
- Connect only the integrations you use, and rotate keys if you suspect they were exposed.
Responsible disclosure
- If you find a vulnerability, write to support@mizup.app with enough detail to reproduce it.
- Please do not test against other customers' data, run denial-of-service tests, or disclose publicly before we have had a chance to fix it.
- We will acknowledge and keep you updated.
MizUp is a product of BrandMiz Private Limited. For questions about this page write to support@mizup.app. You can also reach us through the contact page.
Registered office: BrandMiz Private Limited, U-179, Office No. 303, 2nd Floor, Gali No. 4, Shakarpur, East Delhi, Delhi 110092, India.
Registered office: BrandMiz Private Limited, U-179, Office No. 303, 2nd Floor, Gali No. 4, Shakarpur, East Delhi, Delhi 110092, India.
