PBJ Vault — Changelog
Current release: 1.9.0 (August 2026). One-time purchase per major version; requires PBJ CRM.
1.9.0
A vault entry is now something you can attach things to — tasks, notes and files.
Nothing about the vault itself changes. Only the entry’s name is ever read for this. Every secret stays encrypted and still needs the vault unlocked, exactly as before.
1.8.0
An assistant can now see what sub-databases you have and what fields they hold — their names, the fields on them, how many records in each you are allowed to open, and what they can be pinned to. A field that is protected is named as protected and never read: the assistant is told the field exists and nothing more, and the value never leaves the vault. That was checked with the vault locked, and again with it unlocked, and nothing came out either way. It is reading only — there is no way for an assistant to create, change or delete a sub-database.
1.7.0
“What has changed since” now gives an honest total. Ask an assistant which vault records have changed since a date and the number it reports is the number that really did change, counted after the who-can-see-this rules have been applied, so sharing is untouched. It used to hand back the total for every record you can see, which meant the number and the records listed beside it disagreed. An assistant asking what has changed now gets the complete answer.
1.6.0
The Archive is now the Vault, everywhere you can see. A rename and only a rename: your data, the encryption, the lock, your license and every address are exactly as they were.
1.5.0
Record names, types and pins are available to the CRM’s new assistant connector — never a protected value, and never anything from a locked vault. Requires PBJ CRM 1.29.0 or newer.
1.4.0
The Vault home screen gains a search across every sub-database by name. Records stay out of the suite’s shared search on purpose — vault searching happens only inside the Vault. A locked vault still shows names and types only, never a protected value.
1.3.0
Housekeeping, with nothing touched in the vault. There is no change to encryption, to how the vault locks or unlocks, to who can see what, or to the database — and that is worth saying plainly, because it is the first question anyone asks of an Archive release.
The plugin now checks that PBJ CRM is not just installed but new enough, and says so with one notice instead of failing. It also asks for a slightly newer WordPress, because that is the version where WordPress began enforcing the CRM requirement at all. And if you remove the plugin while choosing to keep your data, its daily background job is now cleared out properly instead of being left pointing at something that is gone.
1.2.0
Internal only. PBJ Archive now declares its eight tables and two settings to PBJ CRM, so a future whole-suite backup includes them. The vault table is flagged as essential — without it, a restored backup’s encrypted values could never be read again — and the entry tables are flagged as needing their record numbers preserved, because those numbers are part of what the encryption checks. Nothing changes on screen, no data is touched, and there is no database change.
1.1.0
PBJ Archive now formally requires PBJ CRM, matching how it is sold: WordPress itself checks for the CRM, and if it is missing you get one plain message instead of a half-working plugin. Revealing a value now honours the “require an unlocked vault even to list records” setting. Signing out also clears your own vault session immediately rather than leaving it to time out. And filing a record from a business profile now offers the right sub-databases for a business.
1.0.0
First release. Sub-databases you design or build from a CSV (secret columns auto-detected); vault encryption (XChaCha20-Poly1305 / AES-256-GCM) under your passphrase with a one-time printed recovery code; reveal-on-click one field at a time with a full audit trail; per-type access levels plus per-record grants; records pinned to PBJ CRM companies, contacts and agents; a 31-point security self-test you can run yourself; plain-words fallback (and an upgrade path) for servers without the fast key-derivation extension.
Current release: 1.9.0 (August 2026). One-time purchase per major version; requires PBJ CRM.
1.9.0
A vault entry is now something you can attach things to — tasks, notes and files.
Nothing about the vault itself changes. Only the entry’s name is ever read for this. Every secret stays encrypted and still needs the vault unlocked, exactly as before.
1.8.0
An assistant can now see what sub-databases you have and what fields they hold — their names, the fields on them, how many records in each you are allowed to open, and what they can be pinned to. A field that is protected is named as protected and never read: the assistant is told the field exists and nothing more, and the value never leaves the vault. That was checked with the vault locked, and again with it unlocked, and nothing came out either way. It is reading only — there is no way for an assistant to create, change or delete a sub-database.
1.7.0
“What has changed since” now gives an honest total. Ask an assistant which vault records have changed since a date and the number it reports is the number that really did change, counted after the who-can-see-this rules have been applied, so sharing is untouched. It used to hand back the total for every record you can see, which meant the number and the records listed beside it disagreed. An assistant asking what has changed now gets the complete answer.
1.6.0
The Archive is now the Vault, everywhere you can see. A rename and only a rename: your data, the encryption, the lock, your license and every address are exactly as they were.
1.5.0
Record names, types and pins are available to the CRM’s new assistant connector — never a protected value, and never anything from a locked vault. Requires PBJ CRM 1.29.0 or newer.
1.4.0
The Vault home screen gains a search across every sub-database by name. Records stay out of the suite’s shared search on purpose — vault searching happens only inside the Vault. A locked vault still shows names and types only, never a protected value.
1.3.0
Housekeeping, with nothing touched in the vault. There is no change to encryption, to how the vault locks or unlocks, to who can see what, or to the database — and that is worth saying plainly, because it is the first question anyone asks of an Archive release.
The plugin now checks that PBJ CRM is not just installed but new enough, and says so with one notice instead of failing. It also asks for a slightly newer WordPress, because that is the version where WordPress began enforcing the CRM requirement at all. And if you remove the plugin while choosing to keep your data, its daily background job is now cleared out properly instead of being left pointing at something that is gone.
1.2.0
Internal only. PBJ Archive now declares its eight tables and two settings to PBJ CRM, so a future whole-suite backup includes them. The vault table is flagged as essential — without it, a restored backup’s encrypted values could never be read again — and the entry tables are flagged as needing their record numbers preserved, because those numbers are part of what the encryption checks. Nothing changes on screen, no data is touched, and there is no database change.
1.1.0
PBJ Archive now formally requires PBJ CRM, matching how it is sold: WordPress itself checks for the CRM, and if it is missing you get one plain message instead of a half-working plugin. Revealing a value now honours the “require an unlocked vault even to list records” setting. Signing out also clears your own vault session immediately rather than leaving it to time out. And filing a record from a business profile now offers the right sub-databases for a business.
1.0.0
First release. Sub-databases you design or build from a CSV (secret columns auto-detected); vault encryption (XChaCha20-Poly1305 / AES-256-GCM) under your passphrase with a one-time printed recovery code; reveal-on-click one field at a time with a full audit trail; per-type access levels plus per-record grants; records pinned to PBJ CRM companies, contacts and agents; a 31-point security self-test you can run yourself; plain-words fallback (and an upgrade path) for servers without the fast key-derivation extension.