DataVault365

Security and encryption

Encryption and access controls for Microsoft 365 backup.

Protection involves more than another copy. DataVault365 combines encrypted storage, role-based access and records of data access and recovery.

Updated 17 September 2026

Encryption of content and file information

Backup content is encrypted at rest using AES-256-GCM. Sensitive metadata, including file names, paths and email subjects, is also encrypted. Keys are separated per customer.

Encryption does not replace careful access management. During an authorised recovery or viewing action, the application must be able to decrypt the required data. Key management and recovery procedures are therefore configured alongside access.

Who can view and recover data?

The customer portal uses Microsoft sign-in. Roles determine which areas users can see and which actions are permitted. Administrator access to protected customer content uses approvals in the portal; viewing and recovery actions are recorded.

Agree in advance who may grant approvals, which data a request covers and who checks the recovery. Limit access to what the task requires.

Check recoverability as well as backup status

A successful backup run is an important signal. A periodic recovery check also shows whether the right data can be found and the selected destination is accessible. Check the restored file or message and the activity record.

Read the documented technical and organisational measures.

Discuss backup coverage and recovery

Tell us how many users and which Microsoft 365 services you want to protect. We will discuss coverage, retention and pricing with you.