August 21 · encrypted receipts
Ciphertext in storage.
Keys in private hands.
Prepare fragment-key claim links and a separately encrypted admin recovery bundle.
Admin encryption
Seal one recipient receipt
Paste a signed portable receipt downloaded from the finalized payroll flow. AES-256-GCM encryption happens locally; storage receives ciphertext, never the key or row JSON.
Claim material
Separate ciphertext from keys
Generate a receipt to create a random 256-bit claim key and encrypted recovery bundle.