Skip to content
Fenwix

Architecture Direction

Zero-Custody is an architecture, not a checkbox.

Zero-Custody is a target enterprise architecture in which inspection records, evidence and reports can be synchronized and used without being routed through or stored in a Fenwix-controlled field-data repository.

Zero-Custody direction showing operational field content outside the vendor control plane.
ARCHITECTURE DIRECTION

Fenwix Solo currently keeps core inspection content in an encrypted app-private database and evidence vault. The customer-controlled, multi-device synchronization and enterprise layers described on this page are not shipped capabilities.

Why the distinction matters

A product can use local storage and still depend on a vendor database for collaboration. It can avoid storing inspection photos while still receiving finding text through telemetry. It can offer customer storage while retaining a proprietary record model that cannot move elsewhere.

Zero-Custody therefore requires more than one storage setting. Data classes, protocol ownership, connector behavior, support access and operational dependencies must be designed together.

Five boundaries

Customer operational content

Inspection answers, notes, evidence, signatures, findings, corrective actions, reports and precise inspection location belong in the customer-controlled data plane.

Vendor control plane

Licensing, entitlement, release management and content-free service status must not require inspection content to perform their function.

Product telemetry

Minimized crash, performance and product signals must exclude site names, asset names, finding text, report content, worker identity and evidence.

Support

Support has no standing access to the customer data plane. Any content sharing is explicit and scoped to a user-initiated support interaction.

Optional external services

Storage connectors, Customer Relay, integrations and optional processing require customer choice, a visible data path and a defined purpose.

Target data path

Authorized Field Device
          ↓
Field Data Protocol
          ↓
Customer-Controlled Storage
          ↓ optional
Customer Relay
          ↓
Customer Enterprise Systems

Fenwix infrastructure is not the default field-data repository in this target path.

Required design principles

  • Local-first commit before synchronization
  • Stable identity for operational records
  • Versioned records and explicit revisions
  • Original evidence retained separately from annotations
  • Provider-independent, machine-readable packages
  • Resumable and idempotent synchronization
  • Explicit conflict states
  • No blind last-write-wins behavior for submitted inspection records
  • Customer-controlled retention and export
  • Content-minimized vendor control plane
  • No default vendor access to customer inspection content

What Zero-Custody does not mean

It does not mean that no network packet reaches Fenwix

Licensing, application updates, the public website and user-initiated support services still exist.

It does not mean that local encryption is remote E2EE

Current Fenwix Solo encrypts its app-private database and evidence-vault objects at rest. User-directed portable output leaves that vault boundary, and no cloud synchronization or remote E2EE is claimed.

It does not eliminate every privacy or security obligation

Metadata, support submissions, connector credentials and optional services still require defined handling, security and retention rules.

It does not make evidence automatically true

Hashes, revisions and signatures can help reveal change and establish provenance. They do not prove that the underlying field statement is correct.

It does not guarantee compliance

Zero-Custody is a data architecture property. Compliance depends on the complete technical, organizational, contractual and legal context.

Current product versus direction

CURRENT

Current Fenwix Solo

  • Offline core inspection workflow
  • Encrypted app-private database and evidence vault
  • Stable record identity and a versioned canonical bundle foundation
  • No Fenwix account required for core use
  • Evidence hashes and source tracking
  • Separate original and annotation model
  • Completed-record revisions
  • Local source-record verification
  • No default support access to inspection content
ARCHITECTURE DIRECTION

Business and enterprise direction

  • Customer-controlled shared storage
  • Provider-independent connector layer and durable transfer queue
  • Explicit conflict handling and tested recovery
  • Organization policy and role-based authorization
  • Cryptographic device and user signing
  • Optional Customer Relay
  • Enterprise integrations and regulated deployment options

Procurement questions this architecture should answer

  • Where is operational field content stored?
  • Can the product operate if Fenwix infrastructure is unavailable?
  • Which data classes can reach Fenwix services?
  • Can support access inspection content by default?
  • Is the record format portable across storage providers?
  • What happens when two devices change the same record?
  • How are revisions, conflicts and evidence relationships preserved?
  • Can the customer retain and export the complete operational history?
  • Which capabilities are current, and which remain roadmap items?

Frequently asked questions

Is Fenwix Zero-Custody today?

The current Solo product keeps core inspection content on the device and does not require a Fenwix-hosted inspection database. The multi-device enterprise Zero-Custody architecture is still a direction, not a shipped capability.

Does Zero-Custody mean Fenwix processes no data?

No. Licensing, updates, website operation, minimized telemetry where configured and user-initiated support remain separate services. The central boundary concerns operational inspection content.

Is customer-controlled storage currently available?

No. Customer-controlled shared storage and its connectors belong to the architecture roadmap.

Is Google Shared Drive already connected?

No. Google Shared Drive is the first planned connector, not a currently available Fenwix integration.

Can Fenwix staff view inspection content?

The current model provides no default support access to inspection content. A user can deliberately include information in a support request.

Evaluate the boundary, not the label.

Review current Fenwix controls separately from the enterprise architecture direction. For the field product and current Android workflow, continue to Fenwix.app.