Backup Vault, a new module inside Dekimu Hub, now connects to GitHub and Stripe with a credential the customer pastes in and takes automated, encrypted backups of that data — sealed to the workspace's own key, with no path on Dekimu's servers to decrypt it. The module went live on September 29, 2026, alongside a DPA annex that states, in contract language, exactly what the credential can and can't be proven to do.
A customer connects a GitHub or Stripe account by pasting in an access key. From that point, Backup Vault pulls the account's data on a schedule and stores it encrypted, using a key that lives only inside that customer's workspace. Content never touches Dekimu's servers in a form Dekimu's servers can read back — the promise is architectural, not a line in a policy document that could quietly stop being true.
GitHub's classic access tokens don't offer a read-only scope. The closest available permission, the classic `repo` scope, is write-capable by design — there's no toggle a customer can flip to make it provably safer. So the annex doesn't claim the key is verified read-only, because nothing in the system checks. It's instructed to be read-only in the setup flow, and warranted to be read-only by the customer who created it. Both of those are real, and neither is the same as a verification the code doesn't perform.
The published text claims exactly what the code can support: the key is instructed read-only and warranted read-only — never verified read-only.
No qualified EU privacy lawyer has reviewed the Backup Vault annex. That was a deliberate choice, not an oversight — external counsel review was ruled out on cost grounds for this surface, the same way it was for an earlier Dekimu module. The annex publishes instead under a self-review posture, with a banner on the page saying review is pending, and it was written to claim less than an earlier internal draft did rather than to paper over the gap. A rotation policy for the credentials — a twelve-month maximum age — is stated as an approved target that hasn't been built yet, not as a control that already exists.
Before the module could go live, a line in its own interface had to change. The connect screen described the credentials as "least-privilege," which doesn't hold for GitHub specifically — there's no lower-privilege scope on offer, so the customer never actually gets to choose one. That fix, and one matching internal comment, shipped a full week before the flag reached Hub. The annex and the interface had to agree with each other, and with what the code could actually support, before either one was allowed to reach a customer.
This post was drafted by an AI system from Dekimu's public engineering record and published with automated checks, without per-post human editing.
← Back to blog