Tenant landing zone
Raw PDFs, spreadsheets, and text files uploaded by the buyer or deal team.
Bucket: rfp-documents
Retention: 30 days
Legal hold: supported
Enterprise data vault
VaultAI now exposes a concrete data-vault control plane: deterministic package manifests, private storage tiers, object-level checksums, RLS-backed package tables, legal-hold retention, and signed evidence roots. This is designed to read like enterprise infrastructure, not a speculative AI demo.
This is the buyer-facing answer to where documents live, how they are promoted, when they are frozen, and how they become evidence.
Raw PDFs, spreadsheets, and text files uploaded by the buyer or deal team.
Bucket: rfp-documents
Retention: 30 days
Legal hold: supported
Parsed text, page citations, chunk metadata, vector anchors, and structured diligence records.
Bucket: rfp-documents
Retention: 180 days
Legal hold: supported
Board-ready reports, hash manifests, audit-chain exports, and diligence conclusions.
Bucket: vaultai-evidence
Retention: 2,555 days
Legal hold: supported
Encrypted source-code vault, trade-secret manifests, and buyer review package.
Bucket: vaultai-escrow
Retention: 3,650 days
Legal hold: supported
Closed deal archives and immutable audit exports.
Bucket: vaultai-archive
Retention: 3,650 days
Legal hold: supported
The package is not a loose folder dump. Each object class has a role, tier, expected volume, hash requirement, and database anchor.
| Object class | Tier | Count | Modeled size | Database anchor |
|---|---|---|---|---|
Raw data-room documents org_id/package_id/raw/001-purchase-agreement.pdf | landing | 3,000 | 18.16 GiB | vault_package_objects.logical_role = raw_source |
Page-level text extracts org_id/package_id/extracts/001-purchase-agreement/pages.jsonl | processing | 50,000 | 381.47 MiB | document_chunks.metadata.page_number |
Vector-indexed chunk records postgres.public.document_chunks | processing | 125,000 | 417.23 MiB | document_chunks.embedding + document_chunks.metadata |
Buyer evidence reports org_id/package_id/evidence/vdr-summary.json | evidence | 48 | 34.33 MiB | vault_audit_events.event_type = evidence_exported |
Encrypted IP escrow vault vaultai-escrow/source/VAULTAI_ENTERPRISE_IP_LOCKED.enc | escrow | 1 | 209.81 MiB | vault_packages.package_type = source_escrow |
Hash-chained audit events postgres.public.vault_audit_events | evidence | 25,000 | 24.41 MiB | vault_audit_events.event_hash |
The database story is explicit: package tables are tenant-scoped, high-cardinality lookups are indexed, and saturation signals become evidence.
supabase/enterprise_data_vault.sql enables RLS and uses organization_memberships checks.
A reviewer can see that cross-tenant package leakage is blocked at the database boundary.
Every object class has a content_sha256 anchor and package-level manifest root.
The buyer can validate exactly which data-room objects were processed or exported.
vault_retention_policies and vault_packages.legal_hold control deletion eligibility.
Compliance teams get clear lifecycle language instead of ad hoc file deletion.
The migration defines org/state, package/role, hash, audit, and health snapshot indexes.
Diligence-room navigation remains responsive as package and object counts grow.
Runtime DATABASE_URL must point to the Supabase pooler; HTTP clients remain bounded.
A burst of reviewers does not become an unbounded database-connection incident.
vault_database_health_snapshots records connection, queue, p95, and storage growth metrics.
Procurement teams can review operational saturation signals without guessing.
Each state transition exists to make the platform easier to trust in a real diligence process.
Uploads bypass application memory by using tenant-scoped signed storage paths and object-size admission checks.
Every object receives a SHA-256 anchor before downstream extraction is accepted.
A package manifest binds source objects, extracted text, embeddings, evidence files, and audit rows to one manifest root.
The package cannot move to reviewed state unless object count, bytes, and hash roots match.
Extraction jobs, chunks, package objects, and audit events live behind organization-scoped RLS and explicit authenticated grants.
Membership-based RLS prevents cross-tenant reads while service workers retain controlled background processing.
Retention policies separate hot review, warm evidence, cold archive, and destroy-after windows with legal-hold override.
Deletion eligibility is derived from retention_until and legal_hold, not a frontend button.
Buyer-facing evidence packages export root hashes, package state, storage tier, database snapshot, and audit-chain metadata.
The exported manifest can be verified without exposing private source documents.
This control plane is deployable schema and application logic. It does not claim a completed independent SOC 2 audit, bank pilot, or proof that any buyer will pay a specific price.
VaultAI is not just a file uploader; it packages large diligence rooms into a governed evidence graph with deterministic hashes, retention policy, audit chain, and RLS-enforced database state.
Open JSON manifest