Where your register lives
You pick this at setup, and it decides everything else on this page.
This Mac and my devices
Your register stays on your hardware. Your phone syncs to your Mac across your own network. There is no account, no telemetry or analytics, and none of your inventory reaches us. The only thing that can is a support message you choose to send, which carries the app version and your OS, and can carry your organisation’s name and account email unless you switch those off.
Starkive Cloud
Your register syncs through a database we run, so a Mac and an iPhone can hold the same one. The rest of this page is about this option.
What we can read
Part of a cloud register sits on our server in a form we could read. Part of it does not. Here is the line.
| We can read this | We cannot read this |
|---|---|
| Asset tags, serial numbers, makes and models | Which regulated data a device carries: cardholder data, health data, controlled unclassified information or EU personal data |
| Who holds a device, and which site it is at | Disposal evidence: the witness, the wipe certificate, who authorised and verified it |
| Status, purchase and warranty dates, purchase prices, lease dates, and contracts with their costs, including a lease contract's monthly cost | An asset's own lease rent and the costs behind it |
| Hostnames and MAC addresses, operating system and version, device management and when a device was last seen | Whether a recovery key is escrowed |
| Whether a device carries regulated data at all (yes or no), and its classification | Condition and return notes |
| Custom field names, types and choices | What you type into custom fields |
| Who wrote an asset off its book value, and when | Photographs and file attachments, with their names and notes |
| Loss and theft reports: status and dates | The reasons and police report numbers on a loss or theft report |
| Audit evidence: approved to connect and who reviewed it, business use, end of support, due back, received, invoice number, GL account, depreciation method, disposal proceeds and ITAD vendor, sanitisation tool version and verification method | What changed, in audit trail entries written by the apps |
Some things never reach us at all. IP addresses are typed in by you, kept on your own devices, and never sent to Starkive Cloud. The same goes for the values of any custom field you set to Keep off Starkive Cloud; its name and choices still sync so every device knows it is there. A paired Mac and iPhone can share both over your own network.
Until an owner sets up encryption for the organisation, the right column waits on your devices and is not sent at all. Setting it up takes a minute, happens once, and cannot be undone.
The right column is encrypted on your device with a key we never receive. We cannot read it, we cannot hand it to anyone who asks for it, and we cannot get it back for you if you lose every device and your recovery phrase.
Jobs and requests are on the readable side too: their titles and notes, their numbers (like JOB-0001), a job’s due date, and who checked a job’s report and when. They are your organisation’s records, kept so every device sees the same queue.
The left column is readable on our side on purpose. It is what makes search and sync quick. If that is not acceptable for your fleet, the answer is a local workspace, not a smaller cloud plan.
The audit trail
Every change to an asset is recorded. For changes made in the apps, what changed is encrypted like the right column above. Which asset, when, and the account email that made the change are not, because the server has to order and filter on them.
- No app and no server key can change or delete a row. The database refuses it, rather than our code choosing not to. The only exceptions are deleting a whole workspace and erasing a person’s name when asked, and each leaves a receipt.
- Every row carries a fingerprint of the row before it. Alter one in the middle, or take one out, and every row after it stops adding up.
Two kinds of change keep the field and its new value readable: changes made through the API, and some edits sent by older iPhone builds. Treat the trail as partly readable, not encrypted. A change to an IP address, or to a field kept off Starkive Cloud, reaches the trail in the cloud as the fact that something changed, without the old or new value.
The limit, since you would find it eventually: this does not yet prove that the newest rows were not removed. Catching that needs a copy of the last fingerprint kept on one of your own devices, which is what we are building next. Until then the trail is append-only because access control says so, and tamper-evident because the fingerprints say so. It is not yet tamper-proof.
Locking the app
Both apps can ask for Face ID, Touch ID or your password before they open the register.
Off unless you turn it on, in Settings. There is a grace period so you are not authenticating every few minutes (15 minutes on the Mac, 3 on the iPhone), and a Lock now button for when you hand the machine to somebody. On the iPhone the lock covers everything, including a record or form you had open.
Be clear what it is: it stops a person picking up an unlocked device and reading your asset list. It is not encryption, and it does not protect the file from somebody who takes the disk.
Turn on FileVault
Your register on a Mac is a database file, and Manifest does not encrypt it. Encryption happens when data is sent to Starkive Cloud.
Anyone with the drive out of your Mac can read your asset list, and the app lock above does nothing about that. FileVault is what does, and Manifest assumes it is on. If you are keeping a register for anyone other than yourself, treat it as a requirement rather than a suggestion. On iPhone the equivalent is on as soon as the phone has a passcode. Backups and CSV exports are not encrypted either, so keep them somewhere only you can reach.
Pairing a phone to a Mac
The first time your iPhone connects to your Mac, both screens show a code. Compare them before you accept.
After that the phone will only talk to that Mac, and refuses anything pretending to be it. The link is TLS with a pinned certificate. So the attention worth spending is all on that one moment, on your own network, and none of it afterwards.
If the phone already holds asset changes when it first pairs, it holds on to them and asks: send them to this Mac, hand them over for review, keep them for now, or discard them. None of them goes until you choose. Before sending, the phone asks the Mac whether those tags and serials are already in use, and that question stays on your own network.
Whether the Mac answers on your network at all
It does not, until you say so. This is one switch, it starts off, and it survives a restart in whichever position you left it.
A fresh install opens no port and advertises nothing. Turn on Serve this network in Settings and the Mac starts listening on TCP 7277 and advertising a Bonjour service so a paired iPhone can find it. Turn it back off and the port closes; it does not merely hide the button.
This is also the answer we gave Apple when an automated scan asked why the app declares the entitlement that accepts inbound connections. The scan could not find the functionality precisely because the listener is built only after somebody opts in.
What is on an NFC tag
One HTTPS link carrying the register's own key for that machine, and nothing else.
No asset number, no serial, no make or model, no holder, nothing naming your organisation. A chip can be read by anyone who walks past it, with no pairing, no authentication and no trace, so the chip carries a pointer and the register holds the facts.
And it is the one thing here that cannot be re-keyed. Everything written to a tag sits permanently outside the client-side encryption. It cannot be rotated when an admin leaves, revoked, or scoped to a role. That is the whole reason nothing sensitive is put on one. Printed asset numbers are issued per organisation, so the same number names a different machine at every company using that prefix, which is a second reason to keep it off the chip.
A tag written by Manifest is a link to starkive.app/a/…. If somebody without the app taps it, they reach a page that explains what they are holding and can tell them nothing about the machine, because we do not have it.
If you connect your own tools
Manifest has a REST API for pointing your own systems at your register.
- You choose what each key can read. Every field is a switch, so a scanner that only needs serial numbers does not also receive holder names, prices and network addresses. Every field is listed on the API page.
- A key is shown once. We keep only a fingerprint of it, so we cannot show it to you again, only replace it.
- Keys stop working after a year. You renew one from the app, and that is deliberate: the key nobody has thought about for four years is the one that gets left behind.
- A key is limited to 120 requests a minute.
- Keys reach the readable half only. The encrypted half is not available through the API at all, whatever a key is configured to ask for.
Who else touches your data
| Who | What for | Where |
|---|---|---|
| Supabase | The database and file storage behind a cloud workspace | United States |
| Apple | App Store purchases and subscriptions. We never see your card | Per Apple |
| Cloudflare | This website. No customer data goes near it | Global |
| Resend | Emails us a support message you send from the app, if you send one | United States |
A local workspace involves none of them except Apple, for the purchase, and Supabase and Resend if you send us a support message.
What we do not collect
We do not record your IP address in anything we build. Supabase, which runs Starkive Cloud, and Cloudflare, which serves this website, keep standard request logs that include it. IP addresses on your asset records never reach Starkive Cloud. No analytics inside the apps. No tracking, no advertising identifiers, and nothing sold or shared. The full detail is in the privacy policy.
Found a problem?
Email support@depaloconsultingllc.com with SECURITY in the subject. Tell us what you found and how to reproduce it. We will confirm we have it, and we will not argue with you about whether it counts.