Security & data protection

Private by design.
Recoverable by practice.

FMS is designed to keep operational records on devices you control, protect sensitive data at rest and in transfer, make important changes detectable, and give you deliberate recovery tools. Security is a layered system, not a single feature.

01 / LOCAL OWNERSHIP

No required cloud database

The Windows application stores its operational database locally for the signed-in Windows user. Normal collection management does not depend on a hosted FMS account or a continuous internet connection.

  • Your primary records remain on your computer.
  • The Android companions keep drafts in application-private storage.
  • Transfers are explicit and reviewed rather than automatic cloud synchronization.
02 / ENCRYPTION AT REST

Protected data and protected keys

The Windows database uses SQLCipher encryption. Its database key is separately protected for the current Windows user with Windows Data Protection API (DPAPI), so copying the database file alone is not enough to open it.

  • Attachments are stored inside the encrypted data layer.
  • Android drafts and photos use authenticated AES-GCM encryption backed by a non-exportable Android Keystore key.
  • Cached offline licensing material is also protected for the Windows user.
03 / AUDIT INTEGRITY

Important changes leave evidence

Security also means understanding what happened. Important actions are appended to an audit history protected by database rules and a SHA-256 hash chain.

  • Append-only enforcement resists ordinary alteration through the application.
  • Chain verification identifies missing or changed audit entries.
  • Attachment access, imports, exports, backups, restores, and other sensitive workflows are auditable.
04 / BACKUP & RECOVERY

Backups are verified before trust

FMS creates encrypted backups and provides verification and recovery-rehearsal workflows. Restore is deliberate and integrity checks run before the active database is replaced.

  • Backup integrity and audit history can be verified.
  • Recovery can be rehearsed in isolation.
  • Destructive reset workflows create and verify a recovery backup first.
05 / PRIVATE MOBILE TRANSFER

Authenticated, computer-specific transfer

Paired Android transfers use a computer-specific Windows identity, fresh ephemeral ECDH P-256 key agreement, and AES-256-GCM authenticated encryption. The Windows private identity is protected with DPAPI.

  • Pairing displays a SHA-256 public-key fingerprint.
  • Each paired transfer derives a fresh encryption key.
  • Pairing can be revoked and rotated from Windows.
06 / SOFTWARE & SUPPORT

Verify what runs and what leaves

Standalone updates are retrieved over HTTPS and checked against published cryptographic information before installation. Privacy-safe problem reporting previews a redacted technical bundle before it is sent.

  • Update integrity is verified before launch.
  • Support bundles exclude collection records, serial numbers, attachments, encryption keys, identities, and personal paths.
  • Export and support actions remain visible user choices.

Know the boundary: encryption cannot protect data from someone who has already compromised your signed-in Windows account or unlocked Android device. Device security, strong account credentials, operating-system updates, protected backups, and physical control remain essential parts of the security model.