Customer operational content
Inspection answers, notes, evidence, signatures, findings, corrective actions, reports and precise inspection location belong in the customer-controlled data plane.
Architecture Direction
Zero-Custody is a target enterprise architecture in which inspection records, evidence and reports can be synchronized and used without being routed through or stored in a Fenwix-controlled field-data repository.

Fenwix Solo currently keeps core inspection content in an encrypted app-private database and evidence vault. The customer-controlled, multi-device synchronization and enterprise layers described on this page are not shipped capabilities.
A product can use local storage and still depend on a vendor database for collaboration. It can avoid storing inspection photos while still receiving finding text through telemetry. It can offer customer storage while retaining a proprietary record model that cannot move elsewhere.
Zero-Custody therefore requires more than one storage setting. Data classes, protocol ownership, connector behavior, support access and operational dependencies must be designed together.
Inspection answers, notes, evidence, signatures, findings, corrective actions, reports and precise inspection location belong in the customer-controlled data plane.
Licensing, entitlement, release management and content-free service status must not require inspection content to perform their function.
Minimized crash, performance and product signals must exclude site names, asset names, finding text, report content, worker identity and evidence.
Support has no standing access to the customer data plane. Any content sharing is explicit and scoped to a user-initiated support interaction.
Storage connectors, Customer Relay, integrations and optional processing require customer choice, a visible data path and a defined purpose.
Authorized Field Device
↓
Field Data Protocol
↓
Customer-Controlled Storage
↓ optional
Customer Relay
↓
Customer Enterprise SystemsFenwix infrastructure is not the default field-data repository in this target path.
Licensing, application updates, the public website and user-initiated support services still exist.
Current Fenwix Solo encrypts its app-private database and evidence-vault objects at rest. User-directed portable output leaves that vault boundary, and no cloud synchronization or remote E2EE is claimed.
Metadata, support submissions, connector credentials and optional services still require defined handling, security and retention rules.
Hashes, revisions and signatures can help reveal change and establish provenance. They do not prove that the underlying field statement is correct.
Zero-Custody is a data architecture property. Compliance depends on the complete technical, organizational, contractual and legal context.
The current Solo product keeps core inspection content on the device and does not require a Fenwix-hosted inspection database. The multi-device enterprise Zero-Custody architecture is still a direction, not a shipped capability.
No. Licensing, updates, website operation, minimized telemetry where configured and user-initiated support remain separate services. The central boundary concerns operational inspection content.
No. Customer-controlled shared storage and its connectors belong to the architecture roadmap.
No. Google Shared Drive is the first planned connector, not a currently available Fenwix integration.
The current model provides no default support access to inspection content. A user can deliberately include information in a support request.
Review current Fenwix controls separately from the enterprise architecture direction. For the field product and current Android workflow, continue to Fenwix.app.