Rhea Ecosystem — RED · Rhea Key · Rhea ID

Store data anywhere.
Keep it readable under your control.

Cloud becomes storage, not trust.

Your data stays yours — even in the cloud.

Rhea Holdings SRL

What RED is

Control infrastructure for enterprise data.

RED is enterprise data protection and management infrastructure — not an encrypted storage service. Organizations keep their chosen storage environment, while RED controls how sensitive data is protected, organized, authorized, accessed, shared, moved and audited.

Storage holds protected objects. RED governs how they become readable and usable.

RED is designed for organizations that need to keep sensitive information in their selected cloud environment while separating possession of stored objects from permission to make protected content readable.

Why RED exists

Storage access is not the same as data readability.

Cloud credentials and storage permissions determine who can reach stored objects. RED adds a separate protection and authorization model around sensitive file content. Possession of a protected object — whether reached through normal administration, copied storage credentials, or a storage incident — is not by itself sufficient to make that content readable.

Client-side encryption is one enforcement mechanism inside RED; RED's category is enterprise data protection and management infrastructure.

If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.

RED command center

One command center for enterprise data control.

RED gives organizations one environment to protect, organize, authorize, access, share, move and audit sensitive data across supported storage environments. The organization keeps control of where data is stored; RED maintains the protection and access model around it.

Protect · Organize · Authorize · Access · Share · Move · Audit

Protected file content is encrypted client-side before reaching connected storage. Rhea's infrastructure has no independent ability to decrypt it.

Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.

rhea.red
RED Command Center — encrypted operations dashboard

Interface preview — example data is synthetic.

Current RED operating model

Authority above. Storage below. RED in between.

Organizational authority

Owner · Admin · Member

Organizational permissions govern who may request sensitive actions.

Human authorization

Rhea Key · Supported Trezor hardware

Authentication, signing and approval on the user's device.

RED control infrastructure

Protect · Organize · Authorize · Access · Share · Move · Audit

The protection, authorization and audit model around your data.

Organization-selected storage

AWS S3

The organization's own AWS S3 environment.

This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.

Data. Authorization. Identity. One security architecture.

REDDataRhea KeyAccessRhea IDIdentity

Architecture

Three products.
One security architecture.

Rhea separates data protection, authorization and identity into distinct responsibilities. RED governs protected data. Rhea Key authorizes people and actions. Rhea ID is planned to establish verified identity or attributes. Rhea Key and Rhea ID do not receive protected file contents.

The three lanes describe product responsibilities. They are different from the RED operating model, which describes how an organization currently uses RED with Rhea Key and its selected storage.

Separating data protection, authorization and identity reduces the amount of sensitive information any one Rhea product needs to handle. Rhea Key and Rhea ID do not receive protected file contents. A storage provider receives encrypted file content rather than readable protected content.

01

Data

RED

Protected file content is encrypted client-side with AES-256-GCM before it reaches connected object storage. Bring Your Own Storage — AWS S3 today.

02

Authorization

Rhea Key

Cryptographic authentication, signing and approval on the user's device. Does not receive or process protected file contents. Web and Android today; iOS coming soon.

03Status: Coming soon

Identity

Rhea ID

Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Not required for current RED operations.

Products

Three products. Three responsibilities.

01 · Data

RED

Enterprise data protection and management infrastructure. Protected file content is encrypted client-side before it reaches the organization's own storage — Bring Your Own Storage, starting with AWS S3.

02 · Authorization

Rhea Key

Cryptographic authentication, signing and approval on the user's device. Private authentication material remains protected by the device and is not transmitted to Rhea. Web and Android available; iOS coming soon.

03 · IdentityStatus: Coming soon

Rhea ID

Coming soon. Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Rhea ID does not carry RED protected-file contents.

Availability

What is available today.

Today, RED supports human-controlled protected-file operations with organization-selected AWS S3 storage. Rhea's direction is to extend RED's protection, authorization and audit model to additional storage providers, supported databases, authorized applications and controlled agent workflows. Those integration interfaces are planned and are not currently generally available.

Status: AvailableGenerally available today.Status: Coming soonIn development, not yet available.Status: PlannedProduct direction, not currently generally available.

Outside these status tables, only limitations are labelled: an item shown without a status marker is generally available today.

Products and clients

Products and clients
ProductStatusMeaning
REDStatus: AvailableEnterprise data protection and management infrastructure
Rhea Key WebStatus: AvailableCryptographic authentication, signing and approval
Rhea Key AndroidStatus: AvailableCryptographic authentication, signing and approval
Rhea Key iOSStatus: Coming soonPlanned iOS client
Rhea IDStatus: Coming soonVerified identity or selected attributes

Not available today

  • Public RED API or SDK documentation
  • Generally available application integration
  • Generally available agent integration
  • BYOD and database integrations
  • Multi-cloud object-storage support beyond AWS S3
  • Rhea ID
  • Rhea Key iOS

These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.

RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.

BYOS · Provider independence

Your data stays where you choose.

With BYOS, RED protects data in your own storage — without moving it into Rhea-owned infrastructure.

Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.

RED control infrastructure

Protect · Organize · Authorize · Access · Share · Move · Audit

Supported and planned storage

Amazon S3

Azure Blob Storage

Status: Planned

Google Cloud Storage

Status: Planned

Cloudflare R2

Status: Planned

Oracle Cloud Object Storage

Status: Planned

S3-compatible storage

Status: Planned

RED separates its protection and authorization model from the storage provider. AWS S3 is supported today; broader provider portability depends on planned integrations.

BYOS

Bring Your Own Storage

Connect your organization's AWS S3 environment. Protected file content is encrypted client-side before it reaches the provider, and RED maintains the protection, authorization and audit model around it.

BYOD

Status: Planned

Bring Your Own Database

Planned. Intended to extend RED's protection, authorization and audit model to supported database environments. Not currently generally available.

Planned data-environment support

Status: Planned
PostgreSQLMySQLSQL ServerOracleMongoDBSupabaseFirebaseSnowflakeBigQueryDatabricks

Named environments indicate direction only. None is currently generally available.

Your data, your controlProtected before storageProvider-independent designAuditable by design

RED Pricing

Choose a plan based on your organization's data volume, usage, and deployment needs.

RED usage is based on the amount of data RED processes each month. This includes encryption, decryption and other processing performed by RED. VAT may apply. Plans are activated inside RED after organization setup.

All plans include client-side encryption and BYOS. RED offers a native 7-day trial — no card required to start a conversation.

Relay usage: In some situations, data may be processed through RED relay instead of the normal direct storage path. Only that portion is billed at the relay rate (10×).

Launch

LAUNCH

€399

/ org / mo

€0.60

billed data (GiB)

  • Client-side AES-256-GCM
  • Bring Your Own Storage
  • Access, permission and approval activity recorded.
View Plan

Growth

GROWTH

€1,499

/ org / mo

€0.15

billed data (GiB)

  • Client-side AES-256-GCM
  • Bring Your Own Storage
  • Access, permission and approval activity recorded.
View Plan

Expand

EXPAND

€2,799

/ org / mo

€0.08

billed data (GiB)

  • Client-side AES-256-GCM
  • Bring Your Own Storage
  • Access, permission and approval activity recorded.
View Plan

Scale

SCALE

€4,999

/ org / mo

€0.05

billed data (GiB)

  • Client-side AES-256-GCM
  • Bring Your Own Storage
  • Access, permission and approval activity recorded.
View Plan

Custom

ENTERPRISE

Volume-based enterprise pricing

Talk to enterprise

Tailored terms for regulated, high-volume, or hybrid deployments.
  • Dedicated onboarding
  • Custom SLAs & regions
  • Priority support
Talk to enterprise

Estimate monthly usage

Pricing estimator

Estimate how much data RED will process each month to see your expected monthly cost.

GiB

All data RED encrypts, decrypts or otherwise processes for your organization.

Estimated monthly total

€1,799.00

on the Growth plan

Operations
2,000 GiB
Plan
Growth
Base fee
€1,499.00
Usage charge
€300.00
Estimated monthly total
€1,799.00

This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside RED.

Trust & privacy

Protected before storage.

Client-side encryption

Protected file content is encrypted with AES-256-GCM on the user's device before it reaches connected object storage. Each protected document is encrypted with its own data-encryption key, wrapped for authorized recipients.

Non-custodial approvals

Rhea Key signs approvals on the user's device. Private authentication material remains protected by the device and is not transmitted to Rhea. Rhea does not operate a key-recovery service.

Audit & accountability

RED records access attempts, permission changes, approvals, organization administration, encryption and decryption operations, and relevant protected-document lifecycle events. Audit records contain operational metadata, not readable protected content.

Bring Your Own Storage

Your organization keeps ownership of the underlying AWS S3 environment. Only encrypted protected-file content reaches it; RED and Rhea still process the operational metadata required to provide authorization, administration, metering, security and audit functions.

No advertising, no scanning

RED does not sell customer data, build ad profiles, or scan protected content for advertising.

Identity kept minimal

Coming soon. Rhea ID is intended to let a service confirm a required identity fact or attribute without the user repeatedly distributing more personal information than the decision requires.

Where Rhea is going · Planned

Extending organizational control to every authorized actor.

Rhea's direction is to extend RED from human-controlled protected-file operations to supported databases, applications and controlled agent workflows. Planned interfaces are intended to let authorized systems request narrowly scoped operations under organizational policy, required human approval and audit.

Status: Planned

Databases

Extend RED's protection, authorization and audit model to supported database environments.

Bring Your Own Database and every named database integration are planned and not currently generally available.

Status: Planned

Applications

Allow authorized applications to request narrowly scoped operations through defined interfaces.

No public application-integration interface, API or SDK is available today.

Status: Planned

Agents

Allow controlled agent workflows to request approved access without receiving unrestricted visibility into organizational data.

No agent integration surface is available today.

These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.

See architecture and direction

Store data anywhere. Keep it readable under your control.