Help centre / Your own backup copy

Security

Keep your own backup copy.

We back up the platform so we can rebuild it. That is not the same thing as a copy of your data that you can open and use, and it never will be. This is the fifteen minute job that makes your business independent of us.

15 minutes, then monthly

Why your own copy is not optional

We take encrypted backups of every vault, replicated to a second Australian server. Those exist so that we can recover our own infrastructure from a failed disk or an operator mistake.

They are not a copy of your passwords that anyone can hand you, and that is by design. Your vault is encrypted with keys derived from master passwords we never receive, so nothing in our backups can be read, searched or partly restored by us. If your entire business lost every master password tomorrow, our backups would be a pile of encrypted bytes to everybody, us included.

This split is in your Terms of Service, and it works both ways. Keeping the platform alive is our job. Holding a usable copy of your own data is yours. We would rather say that plainly on a help page than bury it in clause 14 and surprise you later.

An export also covers the boring, likelier situations:

Which format to choose

The export screen offers several. The choice matters more than it looks, because one of the encrypted options is useless as a disaster backup.

FormatUse it
.json encrypted, password protectedYes, this one. You set a file password. Anyone with the file and that password can restore it into any vault, which is exactly what a backup is for.
.json encrypted, account restrictedNo. It can only ever be imported back into the same account that made it. If that account is the thing you lost, the backup is worthless.
.json plain textOnly for a quick inspection, deleted immediately. It is every password readable in a text file.
.csv plain textSame warning. Useful if you are moving to another system that only reads csv.

The file password is a second unrecoverable secret. Make it strong, make it different from your master password, and store it separately from the file itself. A backup and its password in the same drawer is one theft away from being an incident.

Export your organisation vault

You need to be an owner or an admin. Do it in a browser: the export screen is not in the phone app.

  1. Sign in to the web vault

    https://acme.vault.businessops.com.au

  2. Select Tools, then Export

  3. In Export from, choose your organisation, not My vault

    This is the step to get right. Exporting your personal vault backs up your own items and none of the business ones. If you want both, do two exports.

  4. Choose .json (Encrypted), then Password protected

    The screen offers two export types once you pick the encrypted format. Account restricted is the default and is the wrong one. Switch it to Password protected and set the file password.

    The Export screen of a BusinessOps vault with Export from set to Acme Pty Ltd, the file format set to encrypted JSON, and the export type options
    Export from is set to the organisation, not My vault. Note the warning that only organisation items will be exported.
  5. Confirm with your master password and download the file

  6. Rename it with the date

    Something like acme-vault-2026-07-27.json. In two years you will be grateful you can tell which is current.

Attachments and Sends are not included. If you keep important files attached to vault items, download those separately and store them with the export. Everything else, logins, passwords, notes, website addresses and authenticator codes, is in the file.

Enter your vault name to personalise the steps on this page.

https://acme.vault.businessops.com.au

Showing an example address. Enter your own vault name above to personalise these steps.

Check the export actually works

An untested backup is a hope, not a backup. This takes five minutes and you only need to do it properly the first time, then once a year.

  1. Check the file is not empty

    An encrypted export is unreadable, but it should still be a sensible size. A few kilobytes for hundreds of logins is a red flag, and so is a file of zero bytes.

  2. Confirm you can still open it in six months

    Write down, with the file, the exact format you chose and where the file password is kept. Future you will not remember.

  3. Prove a restore, once

    The honest test is importing the file somewhere and seeing your items appear. The safest way to do that without disturbing your live vault is to ask us for a temporary test vault. We will set one up at no charge, you restore into it, you confirm the count matches, and we destroy it. Businesses that have done this once sleep better.

Where to keep it

Keep the last three, delete the rest. Old exports are old passwords, still readable, still sitting there. Every copy you keep is another place a breach could start, so retire them deliberately.

Make it a routine

The businesses that get burned are not the ones that never made a backup. They are the ones that made one in the first month and never again.

Give the job to a person, not to the business. Name who does the export and who checks it was done. A task that belongs to everyone belongs to nobody, and that is how a year goes by.

Next Use your own domain name Related How your vault is protected

Want us to check your first export?

Email hello@businessops.com.au and we will walk through it with you and set up a temporary vault to restore into. Never send us the export file or its password: the point of the exercise is that we cannot read your data.