Skip to content
Fenwix

Current + Required Roadmap

Security

This page separates what is implemented in today's product from the program that must exist before enterprise deployment. Nothing appears as implemented unless it is.

Layered security model separating current product controls, device responsibility and enterprise roadmap work.

Current product controls

  • Encrypted app-private database and evidence vault for inspection data
  • Offline core workflow, no required cloud round-trip
  • No required vendor-hosted inspection database
  • Evidence hashing (SHA-256 at write time) with capture source
  • Original / annotation separation
  • Versioned completed records with mandatory amendment reasons
  • Local report verification with evidence recheck
  • Inspection-content-minimized telemetry
  • No default support access to inspection content

Enterprise security program, before enterprise deployment

ROADMAP

Planned and required, not yet implemented: OWASP MASVS/MASTG review, secure SDLC, dependency / SBOM process, penetration testing, vulnerability disclosure process, signed builds and releases, supply-chain controls, secrets isolation, incident response, connector least-privilege and relay hardening.

Security questions or a vulnerability to report? Write via the support form at fenwix.app/support with the topic “Problem”, do not include confidential inspection records in the message.