Please enable JavaScript to view this site.

pVault® Help

Proper setup and configuration are required to ensure that pVault® can perform all expected operations and functions.

 

Direct your company’s IT staff to review your application server and verify that the settings detailed in the sections below are configured correctly.

 

Full compliance with these System Environment requirements not only ensures continued operation as new features and functionality are introduced, but also serves as a buffer of protection from intrusions like crypto-locker and other forms of Ransomware.

 

 

Application Server Configuration

 

Run all pVault services as a Domain Service Account.

oRecommended account settings (not required):

Password should be set to never expire and set so that users cannot change them.

If you have a company policy that prohibits the non-expiration of passwords, be aware that our services stop running after reboot once the password expires.
Note: You can enter a new password from the services.msc menu.

Run all of the following services as the same Domain Service Account.

oApplication

oJob Poll

oWeb

The Domain Service Account must have full control permissions for the pVault share.

The Domain Service Account must have full control NTFS permissions for the pVault directory.

Your standard Domain user accounts do not need NTFS permissions to the pVault directory.

Your standard Domain user accounts need read-only access to the pVault winclient directory at the share level.
\\%servername%\pvault\deployment\winclient

Ensure that your standard user accounts have read-only access to the pVault client setup at the share level.
\\%servername%\pvault\deployment\client setup\

Ensure that your standard user accounts have read-only access to the Addins directories in Server Files at the share level.
\\%servername%\pvault\deployment\Server Files\

Ensure that your standard user accounts have read-only access to the pVault Application Server Config.
\\%servername%\pvault\deployment\server files\config\peserverconfig.xml

Ensure that your standard user accounts have read-only access to the pVault Reports Directory at the share level.
\\%servername%\pvault\deployment\reports

Ensure that your standard user accounts have read-only access to the pVault Attachment Sync Directory at the share level, if applicable.
\\%servername%\pvault\Attachment Sync

Ensure that the local service account running your SQL server (usually NT Service\MSSQL$PVAULT) has full NTFS permissions to the database directory in our directory.
c:\pvault\database

If you are in a multi-server environment, your Domain Service Account must be able to see all servers in your configuration.

If your accounting software uses an ODBC driver, be sure the client of your accounting software is installed on the Application server.

 

 

Bridge-level Settings

 

At the bridge level, an Accounting Software Service Account is required. The required accounting settings are as follows:

 

The Service Account must have full access inside the accounting software.

Password should be set to never expire and set so that users cannot change them.

If you have a company policy that prohibits the non-expiration of passwords, be aware that bridge connections could stop operating once the password expires.

 

Note: You can limit individual access to particular items inside pVault.

 

 

Firewall/Port Requirements

 

For SQL Server and Client Workstations:
Important: Firewall ports need to be open on all related (SQL, Application, Storage) servers and all client workstations.

oIncoming TCP 1433

oIncoming TCP 1434

oIncoming UDP 1433

oIncoming UDP 1434

oOutgoing TCP 1433

oOutgoing TCP 1434

oOutgoing UDP 1433

oOutgoing UDP 1434

oDynamic Port of SQL server.
Located in SQL Server Configuration Manager > SQL Server Network Configuration > Protocols for pVault > TCI/IP > Properties > IP Addresses

For pVault Application Server:

oWhatever port you have set in the Server Dashboard.

oBy default, this port is 9990. This value is located on the Deployment tab in the Server Dashboard.

For Web Services:

oYour application server should be able to see the outside web through port 80.

oYou application server should be able to see the outside web through https port 443.

Whitelist Requirements for Paperless OCR (Xtracta):

oweb1-akl.xtracta.com (PDFs)

oapp.xtracta.com (user interface)

oapi-app.xtracta.com (API)

oapi-app-ui.xtracta.com (user interface if opened through API)

Recommended:

*.xtracta.com

app.ocr.paperlessenvironments.com

 

 

Version 2024.01.36 7/17/2026
© 2026 Paperless Environments, LLC or its affiliates ("Paperless") or its licensors.  All trademarks mentioned are the property of their respective owners.  Use of non-Paperless trademarks is not an endorsement of any person or product.