Skip to main content

EnVault Management — Centralized Database Control & Automated Dumps

Last updated: September 24, 2026

Privacy Policy

How we protect your database connection credentials, backup metadata, and audit records in EnVault Management.

1. Database Connection Data & Credentials

EnVault Management operates on a zero-trust architecture designed for mission-critical infrastructure:

  • Connection Credentials: Passwords and connection URIs are encrypted using AES-256-GCM before persistence in the PostgreSQL 16 control database.
  • Dump Metadata: We record file sizes and execution timestamps.
  • Audit Logging: Immutable audit logs capture actor ID, role, originating IP address, timestamp, and operation payload diffs.

2. Data Sovereignty

EnVault Management does not transfer database dumps to external third parties. All backups stream directly to your configured Cloudflare R2 / AWS S3 buckets or local infrastructure volumes.

3. Encryption & Network Security

All API communication and database target connections require TLS 1.3 / strict SSL. Dump streaming occurs in-memory via buffered streaming pipelines without temporary unencrypted disk writes.

4. Retention & Automated Pruning

Configurable retention windows (e.g. 7, 30, or 90 days) allow automated background cleanup jobs to prune orphaned and expired dumps, optimizing object storage costs.