Security, in plain English.

Mee holds employee data behind single sign-on, so your IT team will have questions. This page answers them the way we would in the room: directly, without badge-collecting or vagueness. If anything you need is missing, ask us and we will answer in writing.

How Mee protects your people's data.

Identity & access

Everyone signs in through your single sign-on, on mobile and web alike. No shared logins, no passwords for you to manage, and access follows your joiner and leaver process automatically. Admin permissions are role-based and granted by you.

Encryption

Data is encrypted in transit (TLS) and at rest. Employee submissions, posts and personal data are never sold or shared with third parties for advertising, full stop.

Hosting & residency

Host it your way. Mee runs on major cloud infrastructure such as Microsoft Azure or AWS, or can be deployed within your own organisation's infrastructure where your policies require it. Backups and environment separation are standard, and we confirm regions, residency and the deployment model in writing before contract.

GDPR posture

Mee processes employee data under your instruction as a data processor, with a data processing agreement as part of every contract. Data subject requests are supported, and we keep personal data to the minimum the product needs.

Moderation & safeguarding

Users can report content; authorised admins can edit or remove any post or comment from the web admin. You control who can publish, moderate and see reporting.

Backups & exit

Data is backed up automatically. If you leave, your data leaves with you: content and submissions export in standard formats (CSV), and we delete what we hold on a confirmed schedule.

Your data, not our asset

We hold only what Mee needs to run, and it stays yours. We never sell employee data, never pass it to third parties, and never use it for advertising or to train AI models. It is retained only as long as the product needs it.

Audit & SIEM logging

Security and admin activity is logged with a full audit trail, and those logs can feed your SIEM, so your security team can monitor Mee alongside the rest of your estate.

The questions IT reviewers ask first.

Which SSO providers do you support?

Mee authenticates against your existing identity provider. Tell us what you run (Entra ID, Google Workspace or another provider) and we will confirm the integration during discovery.

Where is Mee hosted, and can we host it ourselves?

Both options are open. Mee runs on major cloud infrastructure such as Microsoft Azure or AWS, or it can be deployed within your own organisation's infrastructure where your security policy requires it. We agree the deployment model, regions and data residency with your IT team during the security review.

What personal data does Mee hold?

The minimum the product needs: name, work identity from your SSO, the content people post, and the form submissions they make. No consumer tracking, no advertising profiles, no data sales.

Can employees use it on personal phones safely?

Yes. Access is per-identity via SSO, sessions can be revoked when someone leaves, and no company data sits outside the app.

How do we run a security review of Mee?

Send us your questionnaire via the contact page and we will complete it in writing. We answer every question directly, including the ones where the answer is "not yet".

Put your hardest question to us.

Bring your IT reviewer to the demo. We would rather answer in the first meeting than stall in the last one.