The idea here is to create a second backend which can work behind the Astral API transparently. Most simply, this might be Postgres KV table with encrypted fields.
Another advantage of this is allowing astral to have "multiple" backends, so that some core secret needed to start Vault could be stored securely ouitside of vault