Backup and recovery
Create and store an encrypted portable bundle
Back up a filing and its evidence with a separately controlled passphrase.
Who can perform the task
Users with access to the filing and the Encrypted filing backup control. Follow organization policy on who may export portable data.
Before you begin
Choose a unique passphrase of at least 12 characters using your approved secret-management method. Decide separate, access-controlled locations for the bundle and passphrase. Confirm retention and data-classification rules.
Quick path
- Select the organization or filing that must be preserved.
- Create an encrypted portable bundle and choose a strong passphrase.
- Download the completed bundle and verify its manifest and checksum.
- Store the bundle and passphrase separately in approved locations.
- Test the documented recovery procedure without overwriting active production work.
Detailed guidance
- Open the filing and expand Encrypted filing backup.
- Enter the passphrase.
- Select Create portable bundle.
- Wait for Encrypted filing bundle created and save the
.sgbundlefile. - Store the bundle and passphrase separately.
- Record the backup identity, filing, date, custodian, and retention date without recording the passphrase in the filing.
Expected result
A locally downloaded encrypted bundle represents the filing’s portable backup at creation time.

The passphrase warning is visible before bundle creation.
How to verify
In an approved test environment, perform a restore rehearsal using the saved file and passphrase. Confirm the restored filing’s identity and representative values.
Common problems
Browser download restrictions can hide the file. Check approved downloads. If bundle creation fails, do not copy the passphrase into a support ticket.
Security and recovery consequences
A lost passphrase makes the bundle unrecoverable unless your organization established its own escrow. Anyone with both bundle and passphrase may be able to access filing data. Rotation requires creating a new bundle.
Product limitations
A portable bundle does not replace coordinated database, artifact-store, and infrastructure backups for the hosted service.