Identity and access
FOVEKI uses authenticated access, invitation-bound entry, Firebase App Check, and Firestore authorization rules. Producer, Lead, Team Workspace, Press Room, and administration surfaces are intentionally separated. A notification or invitation does not itself expand operational authority.
Authority model
Production authority originates with the authorized producer and remains bounded by assigned role and domain. Supporting updates and proposals remain separate from producer decisions. Access removal does not silently rewrite the attributed history needed to understand a production.
Current service providers
Google Firebase provides authentication, databases, functions, hosting, and App Check. Apple provides platform authentication and push-notification delivery. Resend provides transactional email delivery. Connected event-principal services are enabled only for the approved feature and remain governed by their own terms.
Data in transit and on devices
FOVEKI uses HTTPS/TLS service endpoints. Authorized devices can retain a bounded local continuity snapshot. Snapshot age and pending local actions must remain visible; restored connectivity does not make every local action cloud truth without reconciliation.
Operational history
Consequential records are designed to retain actor, time, source, state, and authority context. Supporting proposals remain unchanged as submitted; later producer decisions are recorded separately. Export and retention requirements are reviewed with each private-release production.
Backups, recovery, and continuity
Cloud service recovery and local show-day continuity are different controls. A local snapshot can support bounded work through an interruption; it can become stale. When service returns, FOVEKI surfaces reconciled, conflicted, and rejected actions for producer review.
Current limitations
FOVEKI does not currently claim SOC 2 certification, a contractual uptime SLA, enterprise SSO, completed independent penetration testing, or universal data-residency options. Those must not be inferred from the product’s trust language. Production-specific security, legal, accessibility, and deployment requirements are reviewed before a pilot proceeds.
Incident and vulnerability contact
Report a suspected security issue, unauthorized access, or privacy concern to support@foveki.com. Include enough information to identify the affected production without sending unnecessary confidential material.