Finetic Trust Centre

Trust should be inspectable.

See what Finetic connects to, how releases are produced, which vulnerabilities scanners report, what testing has actually demonstrated, and where the product still has limits.

Evidence over slogansRaw machine-readable evidence accompanies the plain-language assessment.
Limits stay visibleUnknown and unverified claims are not converted into successes.
Household data stays localMedia, accounts and viewing records remain on the selected server.
Every release is traceableVersion, source revision, image digest and scan digests remain distinct.
Public service status

Current availability and honest history.

Checks run from Finetic infrastructure every 15 minutes. This is first-party monitoring, not an independent SLA service.

Monitoring is startingAwaiting the first public check
Page refreshes every 60 seconds
Awaiting sampleWebsite and documentation
Response
Observed uptime
New monitor
Samples
0
Awaiting sampleInstaller downloads
Response
Observed uptime
New monitor
Samples
0
Awaiting samplePublic preview images
Response
Observed uptime
New monitor
Samples
0
24-hour evidence timelineOne cell per 15-minute observation window
Operational Degraded Not yet observed
Public checks retained0Monitoring began 28 July 2026
Healthy observationsNo missing sample is counted as healthy
Current evidence windowBuilding historyEurope/London
Latest collectionNo completed checkAwaiting first sample
Website and documentation
Installer downloads
Public preview images
24 hours ago12 hours agoLatest check
The collector runs unattended every 15 minutes.Public status data refreshes on this page every minute.
Release evidence

One release, four different proofs.

A test result, component inventory, vulnerability feed and immutable image identity answer different questions. Finetic publishes them separately.

PUBLIC PREVIEWFinetic v0.1.92Released 28 July 2026 · Linux amd64 and arm64
Release gate passed
Vulnerability feed0 fixable High / Critical

A human-readable interpretation that does not hide unfixed or duplicate scanner records.

Open security PDF Raw Trivy JSON
Artifact integrityImmutable OCI digest

The installer resolves the preview tag, records the digest and pins Compose to that identity.

Verify an installation

The complete public evidence policy starts with v0.1.92; Finetic does not pretend earlier preview builds have equivalent records. Open the release evidence index.

Evidence integrity · machine-readable release recordOCI index: ghcr.io/360john360/finetic@sha256:f755291c2e21c6e91548853b8e2a4a02bc18880b40fd6fe59f0383b7c447923dSBOM SHA-256: befe7713c79e72e7d6dd7097623ccafa8e5d70b5d8b37ba21d2df4eabac8cea0Vulnerability report SHA-256: 1bacd28f9b60555a1e060915ca512e09fe6a3e4e54984a51c575c7c487d1fdc0Application assessment SHA-256: e109959dc2da0e6f15e25708e6faaaf6719c27a2627eac7fba35de650443d398
Internet-facing assessment

The public boundary was tested separately.

The release assessment tests a clean application container. The black-box assessment approached Young Studio and Finetic as an unauthenticated Internet user, without repository or secret access.

No critical unauthenticated compromise demonstrated

No administrator session, protected Finetic API, repository, environment file, backup, database console or container-management API was obtained.

96,955 signature requests plus manual attack classes

Coverage included public ports, DNS and certificates, content discovery, injection families, request smuggling and representative OCI image inspection.

Open findings remain public

Email/DNS policy gaps remain, and stopped reviewer/chat hosts could not be application-retested while offline. No result is silently converted into “fixed”.

Read the redacted assessment PDF
Release and update process

From exact source revision to pinned installation.

The Docker and managed Linux channels use different delivery mechanisms. Neither is described as stronger than it is.

  1. 01Exact revision

    A release version and source revision are fixed before the compiled distribution is produced.

  2. 02Release gate

    Tests, static type checks, build validation and compiled-only content rules run before publication.

  3. 03Compiled image

    Separate amd64 and arm64 images are built with BuildKit SBOM and provenance attestations.

  4. 04Immutable identity

    GitHub Container Registry returns a manifest digest; the installer writes that digest into Compose.

  5. 05Administrator update

    Docker never silently changes a running container. The administrator explicitly applies an available image.

Managed Linux update archives

Release manifests are Ed25519-signed and archives are SHA-256 verified before staging.

Docker releases

Docker uses immutable OCI digests plus BuildKit provenance/SBOM attestations. Finetic does not yet claim a separate Cosign/Sigstore signing policy.

Data flow

Your media path and Finetic’s services remain separate.

Arrows show possible connections. Dashed connections occur only when the administrator enables or invokes that feature.

YOUR ENVIRONMENT
Read-only mediaMovies and television
Finetic serverPlanner, API and web client
PostgreSQLAccounts, state and evidence
Your clientsWeb, Fire TV and Android testing
OPTIONAL OUTBOUND CONNECTIONS
Metadata providersSearches and artwork only when configured
Release serviceExplicit update checks and image downloads
Your remote hostnameDirect HTTPS; no Finetic relay

Video files are not sent to Young Studio. The public-preview runtime does not ask a Finetic service for permission to start playback.

Local playbackNo Finetic service required

Media and account traffic remains between the selected client and your server.

Preview entitlementNo periodic check

The public-preview runtime has no installation key, payment method, lease, expiry countdown or playback permission request.

Software updatesExplicit administrator check

Finetic contacts the release service only when checking for updates; Docker updates are initiated by the administrator.

MetadataAdministrator-configured providers

Only searches and artwork requests needed for enabled metadata providers leave the installation. Video files are not uploaded.

Remote accessYour public HTTPS origin

Clients connect to the hostname configured by the administrator. Finetic does not currently relay media traffic.

Website analyticsSelf-hosted, cookie-free

Public-site usage is measured separately from household libraries and playback history.

Backup and recovery guarantees

Clear boundaries beat a vague “backup complete”.

These are product behaviours, not a promise that an untested archive or a single local disk will survive a disaster.

Included

Finetic database state, configuration and application-managed artwork can be retained across container recreation.

Not included

Source media is never copied into a Finetic application backup. Protect the underlying media storage separately.

Integrity before confidence

Archive creation is not treated as proof of recovery. Use off-host copies and periodically restore into a clean environment.

Container recovery

Recreate the stateless application container, retain PostgreSQL and persistent volumes, then validate accounts, catalogue state and playback.

Read the complete backup and clean-restore guide
Current limitations

What Finetic does not claim.

This list is part of the product record. It will change only when released functionality or stronger evidence justifies the change.

Finetic is a young, private-source public-preview product without a completed independent security audit or public bug-bounty programme.

The current Fire TV client is public; Android remains supervised testing and other television ecosystems are not released.

Finetic does not buy a domain, configure a router, issue a certificate or relay traffic when direct remote access is impossible.

Automated playback evidence cannot prove subjective picture quality, speaker mapping or HDR correctness without suitable physical observation.

Public status monitoring began on 28 July 2026. Finetic does not claim uptime before that date or provide a public-preview SLA.

Container CVE feeds include duplicate, disputed and unreachable findings. Raw results are published; reachability is not inferred from severity alone.

Responsible disclosure

Found something we should know?

Email hello@youngstudio.uk with “Security report” in the subject. Include the affected version, safe reproduction steps and impact. Do not send passwords, tokens, private media URLs or unredacted household data.

  • Good-faith, non-destructive research is welcomed.
  • Avoid privacy violations, persistence and service disruption.
  • Allow reasonable time to reproduce and correct a report before publication.