Trust should be inspectable.
See what Finetic connects to, how releases are produced, which vulnerabilities scanners report, what testing has actually demonstrated, and where the product still has limits.
Current availability and honest history.
Checks run from Finetic infrastructure every 15 minutes. This is first-party monitoring, not an independent SLA service.
- Response
- —
- Observed uptime
- New monitor
- Samples
- 0
- Response
- —
- Observed uptime
- New monitor
- Samples
- 0
- Response
- —
- Observed uptime
- New monitor
- Samples
- 0
One release, four different proofs.
A test result, component inventory, vulnerability feed and immutable image identity answer different questions. Finetic publishes them separately.
A readable inventory summary with the raw CycloneDX evidence retained alongside it.
Open evidence PDF Raw CycloneDX JSONA human-readable interpretation that does not hide unfixed or duplicate scanner records.
Open security PDF Raw Trivy JSONFresh restricted container, PostgreSQL 15 and no household media mounts.
Read assessment PDF Machine-readable resultsThe installer resolves the preview tag, records the digest and pins Compose to that identity.
Verify an installationThe complete public evidence policy starts with v0.1.92; Finetic does not pretend earlier preview builds have equivalent records. Open the release evidence index.
OCI index: ghcr.io/360john360/finetic@sha256:f755291c2e21c6e91548853b8e2a4a02bc18880b40fd6fe59f0383b7c447923dSBOM SHA-256: befe7713c79e72e7d6dd7097623ccafa8e5d70b5d8b37ba21d2df4eabac8cea0Vulnerability report SHA-256: 1bacd28f9b60555a1e060915ca512e09fe6a3e4e54984a51c575c7c487d1fdc0Application assessment SHA-256: e109959dc2da0e6f15e25708e6faaaf6719c27a2627eac7fba35de650443d398The public boundary was tested separately.
The release assessment tests a clean application container. The black-box assessment approached Young Studio and Finetic as an unauthenticated Internet user, without repository or secret access.
No administrator session, protected Finetic API, repository, environment file, backup, database console or container-management API was obtained.
Coverage included public ports, DNS and certificates, content discovery, injection families, request smuggling and representative OCI image inspection.
Email/DNS policy gaps remain, and stopped reviewer/chat hosts could not be application-retested while offline. No result is silently converted into “fixed”.
From exact source revision to pinned installation.
The Docker and managed Linux channels use different delivery mechanisms. Neither is described as stronger than it is.
- 01Exact revision
A release version and source revision are fixed before the compiled distribution is produced.
- 02Release gate
Tests, static type checks, build validation and compiled-only content rules run before publication.
- 03Compiled image
Separate amd64 and arm64 images are built with BuildKit SBOM and provenance attestations.
- 04Immutable identity
GitHub Container Registry returns a manifest digest; the installer writes that digest into Compose.
- 05Administrator update
Docker never silently changes a running container. The administrator explicitly applies an available image.
Release manifests are Ed25519-signed and archives are SHA-256 verified before staging.
Docker uses immutable OCI digests plus BuildKit provenance/SBOM attestations. Finetic does not yet claim a separate Cosign/Sigstore signing policy.
Your media path and Finetic’s services remain separate.
Arrows show possible connections. Dashed connections occur only when the administrator enables or invokes that feature.
Video files are not sent to Young Studio. The public-preview runtime does not ask a Finetic service for permission to start playback.
Media and account traffic remains between the selected client and your server.
The public-preview runtime has no installation key, payment method, lease, expiry countdown or playback permission request.
Finetic contacts the release service only when checking for updates; Docker updates are initiated by the administrator.
Only searches and artwork requests needed for enabled metadata providers leave the installation. Video files are not uploaded.
Clients connect to the hostname configured by the administrator. Finetic does not currently relay media traffic.
Public-site usage is measured separately from household libraries and playback history.
Clear boundaries beat a vague “backup complete”.
These are product behaviours, not a promise that an untested archive or a single local disk will survive a disaster.
Finetic database state, configuration and application-managed artwork can be retained across container recreation.
Source media is never copied into a Finetic application backup. Protect the underlying media storage separately.
Archive creation is not treated as proof of recovery. Use off-host copies and periodically restore into a clean environment.
Recreate the stateless application container, retain PostgreSQL and persistent volumes, then validate accounts, catalogue state and playback.
What Finetic does not claim.
This list is part of the product record. It will change only when released functionality or stronger evidence justifies the change.
Finetic is a young, private-source public-preview product without a completed independent security audit or public bug-bounty programme.
The current Fire TV client is public; Android remains supervised testing and other television ecosystems are not released.
Finetic does not buy a domain, configure a router, issue a certificate or relay traffic when direct remote access is impossible.
Automated playback evidence cannot prove subjective picture quality, speaker mapping or HDR correctness without suitable physical observation.
Public status monitoring began on 28 July 2026. Finetic does not claim uptime before that date or provide a public-preview SLA.
Container CVE feeds include duplicate, disputed and unreachable findings. Raw results are published; reachability is not inferred from severity alone.
Found something we should know?
Email hello@youngstudio.uk with “Security report” in the subject. Include the affected version, safe reproduction steps and impact. Do not send passwords, tokens, private media URLs or unredacted household data.
- Good-faith, non-destructive research is welcomed.
- Avoid privacy violations, persistence and service disruption.
- Allow reasonable time to reproduce and correct a report before publication.