All documentation
Security and privacy/02

SOC 2 alignment for local-first teams

Map FenSight's local-first model to common trust controls.

FenSight is not a cloud asset store, so security review looks different from a SaaS platform. This guide explains how local-first behavior maps to SOC 2-style concerns such as data handling, access control, change management, vendor review, and audit evidence without claiming a formal certification.

FenSight is not a cloud asset store, so security review looks different from a SaaS platform. This guide explains how local-first behavior maps to SOC 2-style concerns such as data handling, access control, change management, vendor review, and audit evidence without claiming a formal certification.

  • Core asset review happens on customer-controlled Windows devices and storage locations.
  • FenSight does not host source media libraries or normal board work on FenSight servers.
  • Customer controls such as endpoint encryption, Windows accounts, EDR, backups, and file-share permissions remain the primary control plane.
  • Optional hosted AI providers and remote upload destinations should be reviewed as separate configured processors.
  • Audit evidence should document installer source, version, endpoint controls, backup policy, and approved integration settings.

Connected guides

Follow these related pages when the workflow crosses into setup, search, organization, export, security, or another board-level system.