Current + Required Roadmap
Security
This page separates what is implemented in today's product from the program that must exist before enterprise deployment. Nothing appears as implemented unless it is.
Current product controls
- App-private local storage for inspection data
- Offline core workflow, no required cloud round-trip
- No required vendor-hosted inspection database
- Evidence hashing (SHA-256 at write time) with capture source
- Original / annotation separation
- Versioned completed records with mandatory amendment reasons
- Local report verification with evidence recheck
- Inspection-content-minimized telemetry
- No default support access to inspection content
Enterprise security program, before enterprise deployment
ROADMAP
Planned and required, not yet implemented: encrypted local DB / evidence vault, OWASP MASVS/MASTG review, secure SDLC, dependency / SBOM process, penetration testing, vulnerability disclosure process, signed builds and releases, supply-chain controls, secrets isolation, incident response, connector least-privilege and relay hardening.
Security questions or a vulnerability to report? Write via the support form at fenwix.app/support with the topic “Problem”, do not include confidential inspection records in the message.