Also as this is managed solution, I would offer encrypted offsite "cloud" storage.
Any part of the box fails? Send over a new one the next day which will automatically pull all saved data once the login/password is typed on the setup page.
I'd probably lean the other way. I'd build that so that you could say
"Any part of the box fails? Send over a new one then next day then plug one of the USB sticks in and it'll automatically pull the encrypted saved data from itonce the login/password is entered."
If people are choosing a local box instead of her hosted offering, cloud backup might be a deterrent rather than a feature. For the ultra paranoid you could even sell them a spare which they can keep on-hand to swap in and get back invoicing immediately.
Any part of the box fails? Send over a new one the next day which will automatically pull all saved data once the login/password is typed on the setup page.