Data Vault creates a tenant-scoped logical export or snapshot. PayBlah encrypts it at rest, verifies it before every download, and removes it at the end of your chosen retention period. Restore is not automatic. The app never receives database credentials and never runs a database dump.
Prerequisites
- Workspace plan is Growth or Higher.
- An Admin has pressed Install Data Vault.
- You are the current Owner or Admin. Other roles cannot use the app.
Create encrypted material
- Open the app or go to
/apps/data-vault. The back link is Back to Settings. - Under Create encrypted material, choose Snapshot (dated logical copy) or Export (portable ZIP with CSV, JSON Lines, and a manifest).
- Set Retention to 7 days, 30 days, 60 days, or 90 days (30 days is the default).
- Press Queue encrypted item.
Generation continues after you leave the page. Statuses include Queued, Generating, Ready, Failed safely, Quarantined, Deleting, Deleted, and Expired.
Download or delete
- When status is Ready and retention is still active, press Download verified ZIP. Verification uses SHA-256 before the file is released.
- To remove an item that is not already deleted, expired, or mid-generation, enter a Deletion reason of at least 6 characters and press Delete encrypted material.
- If a human deletion did not finish, press Retry deletion. A deletion receipt stays on the item.
Expected result
You have an encrypted item bound to this workspace. Invoices, payments, customers, and workflows are not changed. Treat downloads as sensitive.
If you cannot open or download
- Page not found or Only the current workspace Owner or Admin can use Data Vault. — wrong role, paused install, or plan gate.
- Failed safely — no unverified material is available.
- Download missing — item is not Ready, or retention has ended.
What this will not do
- It does not restore data automatically and does not dump the database.
- It does not accept uploaded files.
- On remove: queued work is quarantined and encrypted material becomes inaccessible until its existing retention deadline removes it.