August 21 · encrypted receipts

Ciphertext in storage.
Keys in private hands.

Prepare fragment-key claim links and a separately encrypted admin recovery bundle.

Admin encryption

Seal one recipient receipt

Paste a signed portable receipt downloaded from the finalized payroll flow. AES-256-GCM encryption happens locally; storage receives ciphertext, never the key or row JSON.

Claim material

Separate ciphertext from keys

Generate a receipt to create a random 256-bit claim key and encrypted recovery bundle.