Skip to content
Fenwix

Data architecture

Data sovereignty for field operations

Data sovereignty in field operations means knowing where inspection records live, which legal and organizational controls apply, who can access them and whether the customer can move or retain them independently. Fenwix Solo currently keeps core inspection content on the Android device; customer-owned shared storage remains an architecture direction.

Data-sovereignty model covering known location, custody, operational control and record portability.
ARCHITECTURE DIRECTION

Current Solo provides a local, vendor-database-independent foundation. Shared customer-owned storage, connectors and enterprise policy controls are not available today.

CURRENT, SCOPED

Location

The organization should be able to identify the device, storage provider and jurisdiction in which each data class resides.

ARCHITECTURE DIRECTION

Custody

Operational inspection content should not need to pass through a vendor repository by default in the target architecture.

ARCHITECTURE DIRECTION

Control

Access, retention, export and recovery decisions must remain understandable and testable rather than implied by a cloud label.

Architecture flow

FIELD RECORD
      ↓
KNOWN STORAGE LOCATION
      ↓
DEFINED ACCESS + RETENTION
      ↓
PORTABLE CUSTOMER-CONTROLLED RECORD

What does data sovereignty require beyond storage location?

The physical or contractual location of a file is only one part of sovereignty. A useful assessment also covers controller and processor roles, administrative access, encryption keys, support access, retention, backup, deletion, portability and failure recovery.

  • Classify operational content, metadata, credentials and support data separately
  • Identify every organization that can administer or retrieve the data
  • Document what happens during outage, subscription expiry and vendor exit
  • Test export and recovery instead of relying on policy language

What is available in Fenwix Solo now?

CURRENT, SCOPED

The current Solo workflow stores core inspection content in app-private local storage and does not require a Fenwix account or a Fenwix-hosted inspection-content database. Records leave the device only through user-directed functions such as export, sharing, backup or support submission.

  • Offline-first core workflow
  • Local app-private inspection storage
  • No default vendor access to inspection content
  • User-directed export and sharing
  • Local storage is not presented as a complete enterprise sovereignty control

What is the customer-owned direction?

ARCHITECTURE DIRECTION

The target Customer-Owned Data Plane keeps shared operational records in storage controlled by the customer and uses a provider-neutral Field Data Protocol. Fenwix services should coordinate licensing and product operations without becoming the default repository for field content.

  • Stable record identity and version-aware packages
  • Encrypted local data before synchronization pilots
  • Explicit connector permissions and resumable transfer
  • Conflict and recovery behavior that does not silently choose a winner
  • Customer-controlled retention and enterprise policy are separate design decisions

Which procurement questions expose weak sovereignty claims?

A product can advertise regional hosting while retaining broad support access, proprietary export or vendor-managed keys. Procurement should test operational boundaries rather than accept a location badge as the complete answer.

  • Can the product perform core work during a vendor outage?
  • Can the customer recover complete records without vendor assistance?
  • Which data classes reach vendor systems and why?
  • Who controls credentials, keys and storage policy?
  • Can a provider change preserve record identity and verification history?

Frequently asked questions

Does local storage automatically provide data sovereignty?

No. It reduces vendor custody for current Solo content, but device security, backup, access, retention, legal scope and recovery still need controls.

Does Fenwix host customer inspection records today?

The current Solo architecture does not require a Fenwix-hosted inspection-content database for core operation.

Can organizations select their own shared storage today?

No. Customer-owned shared storage and connectors are architecture direction, not a current product capability.

Is data sovereignty the same as data residency?

No. Residency concerns where data is located; sovereignty also includes applicable authority, custody, access, portability and operational control.

Does this architecture guarantee regulatory compliance?

No. Compliance depends on the full technical, contractual, organizational and legal implementation for the deployment.

Evaluate sovereignty as an operational property

Separate what Fenwix Solo does now from the customer-owned shared architecture, then verify storage, access, export and recovery for the deployment you are considering.

Content status: ARCHITECTURE_DIRECTION · Last reviewed: 2026-08-16

Claim basis: Fenwix Zero-Custody master plan · Fenwix product decision record · Fenwix.net aligned master brief