Envelope encryption, explained
Each job gets its own random AES-256 data key. That key is wrapped twice: once with a key derived from your job password using PBKDF2, and once with Windows DPAPI bound to the machine. On the original machine restores are seamless; on a new machine your password unlocks them. Lose both, and the data is unreadable — by design.