Enterprise data vault

Packaging, storage, and database management that a real buyer can inspect.

VaultAI now exposes a concrete data-vault control plane: deterministic package manifests, private storage tiers, object-level checksums, RLS-backed package tables, legal-hold retention, and signed evidence roots. This is designed to read like enterprise infrastructure, not a speculative AI demo.

Pages represented
50,000
Objects represented
203,049
Storage modeled
19.2 GiB
Signature
configured
Storage lifecycle

Five operational storage tiers, each with explicit retention and proof behavior.

This is the buyer-facing answer to where documents live, how they are promoted, when they are frozen, and how they become evidence.

Tenant landing zone

Raw PDFs, spreadsheets, and text files uploaded by the buyer or deal team.

Bucket: rfp-documents

Retention: 30 days

Legal hold: supported

Extraction and vector workspace

Parsed text, page citations, chunk metadata, vector anchors, and structured diligence records.

Bucket: rfp-documents

Retention: 180 days

Legal hold: supported

Signed evidence package

Board-ready reports, hash manifests, audit-chain exports, and diligence conclusions.

Bucket: vaultai-evidence

Retention: 2,555 days

Legal hold: supported

Acquisition escrow vault

Encrypted source-code vault, trade-secret manifests, and buyer review package.

Bucket: vaultai-escrow

Retention: 3,650 days

Legal hold: supported

Cold archive

Closed deal archives and immutable audit exports.

Bucket: vaultai-archive

Retention: 3,650 days

Legal hold: supported

Package inventory

Content-addressed objects tie storage paths back to database rows.

The package is not a loose folder dump. Each object class has a role, tier, expected volume, hash requirement, and database anchor.

Object classTierCountModeled sizeDatabase anchor

Raw data-room documents

org_id/package_id/raw/001-purchase-agreement.pdf

landing3,00018.16 GiBvault_package_objects.logical_role = raw_source

Page-level text extracts

org_id/package_id/extracts/001-purchase-agreement/pages.jsonl

processing50,000381.47 MiBdocument_chunks.metadata.page_number

Vector-indexed chunk records

postgres.public.document_chunks

processing125,000417.23 MiBdocument_chunks.embedding + document_chunks.metadata

Buyer evidence reports

org_id/package_id/evidence/vdr-summary.json

evidence4834.33 MiBvault_audit_events.event_type = evidence_exported

Encrypted IP escrow vault

vaultai-escrow/source/VAULTAI_ENTERPRISE_IP_LOCKED.enc

escrow1209.81 MiBvault_packages.package_type = source_escrow

Hash-chained audit events

postgres.public.vault_audit_events

evidence25,00024.41 MiBvault_audit_events.event_hash
Database management

RLS, indexes, retention, pooler discipline, and health snapshots.

The database story is explicit: package tables are tenant-scoped, high-cardinality lookups are indexed, and saturation signals become evidence.

Tenant-scoped RLS on every package table

deployable

supabase/enterprise_data_vault.sql enables RLS and uses organization_memberships checks.

A reviewer can see that cross-tenant package leakage is blocked at the database boundary.

Object-level SHA-256 addressing

implemented

Every object class has a content_sha256 anchor and package-level manifest root.

The buyer can validate exactly which data-room objects were processed or exported.

Retention and legal hold state

deployable

vault_retention_policies and vault_packages.legal_hold control deletion eligibility.

Compliance teams get clear lifecycle language instead of ad hoc file deletion.

Package, object, hash, and audit indexes

deployable

The migration defines org/state, package/role, hash, audit, and health snapshot indexes.

Diligence-room navigation remains responsive as package and object counts grow.

Supavisor transaction-pooler boundary

recommended

Runtime DATABASE_URL must point to the Supabase pooler; HTTP clients remain bounded.

A burst of reviewers does not become an unbounded database-connection incident.

Database-health evidence snapshots

deployable

vault_database_health_snapshots records connection, queue, p95, and storage growth metrics.

Procurement teams can review operational saturation signals without guessing.

Lifecycle

A package moves through controlled states, not random uploads.

Each state transition exists to make the platform easier to trust in a real diligence process.

01

Direct browser-to-storage ingestion

Uploads bypass application memory by using tenant-scoped signed storage paths and object-size admission checks.

Every object receives a SHA-256 anchor before downstream extraction is accepted.

02

Deterministic package assembly

A package manifest binds source objects, extracted text, embeddings, evidence files, and audit rows to one manifest root.

The package cannot move to reviewed state unless object count, bytes, and hash roots match.

03

Database-backed processing

Extraction jobs, chunks, package objects, and audit events live behind organization-scoped RLS and explicit authenticated grants.

Membership-based RLS prevents cross-tenant reads while service workers retain controlled background processing.

04

Legal hold and retention enforcement

Retention policies separate hot review, warm evidence, cold archive, and destroy-after windows with legal-hold override.

Deletion eligibility is derived from retention_until and legal_hold, not a frontend button.

05

Evidence export

Buyer-facing evidence packages export root hashes, package state, storage tier, database snapshot, and audit-chain metadata.

The exported manifest can be verified without exposing private source documents.

Signed control-plane proof

Manifest root
20b53c0739326e7bfa...
Object root
a3f549b14d9c929be8...
DB control root
ede5fed8d578fd8ff9...
Algorithm
HMAC-SHA256

This control plane is deployable schema and application logic. It does not claim a completed independent SOC 2 audit, bank pilot, or proof that any buyer will pay a specific price.

Buyer message

VaultAI is not just a file uploader; it packages large diligence rooms into a governed evidence graph with deterministic hashes, retention policy, audit chain, and RLS-enforced database state.

Open JSON manifest