Rhea Ecosystem — RED · Rhea Key · Rhea ID
Store data anywhere.
Keep it readable
under your control.
Cloud becomes storage, not trust.
Your data stays yours — even in the cloud.
Rhea Holdings SRL
What RED is
Control infrastructure for enterprise data.
RED is enterprise data protection and management infrastructure — not an encrypted storage service. Organizations keep their chosen storage environment, while RED controls how sensitive data is protected, organized, authorized, accessed, shared, moved and audited.
Storage holds protected objects. RED governs how they become readable and usable.
RED is designed for organizations that need to keep sensitive information in their selected cloud environment while separating possession of stored objects from permission to make protected content readable.
Why RED exists
Storage access is not the same as data readability.
Cloud credentials and storage permissions determine who can reach stored objects. RED adds a separate protection and authorization model around sensitive file content. Possession of a protected object — whether reached through normal administration, copied storage credentials, or a storage incident — is not by itself sufficient to make that content readable.
Client-side encryption is one enforcement mechanism inside RED; RED's category is enterprise data protection and management infrastructure.
If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.
RED command center
One command center for enterprise data control.
RED gives organizations one environment to protect, organize, authorize, access, share, move and audit sensitive data across supported storage environments. The organization keeps control of where data is stored; RED maintains the protection and access model around it.
Protect · Organize · Authorize · Access · Share · Move · Audit
Protected file content is encrypted client-side before reaching connected storage. Rhea's infrastructure has no independent ability to decrypt it.
Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.

Interface preview — example data is synthetic.
Current RED operating model
Authority above. Storage below. RED in between.
Organizational authority
Owner · Admin · Member
Organizational permissions govern who may request sensitive actions.
Human authorization
Rhea Key · Supported Trezor hardware
Authentication, signing and approval on the user's device.
RED control infrastructure
Protect · Organize · Authorize · Access · Share · Move · Audit
The protection, authorization and audit model around your data.
Organization-selected storage
AWS S3
The organization's own AWS S3 environment.
This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.
Data. Authorization. Identity. One security architecture.
Architecture
Three products.
One security architecture.
Rhea separates data protection, authorization and identity into distinct responsibilities. RED governs protected data. Rhea Key authorizes people and actions. Rhea ID is planned to establish verified identity or attributes. Rhea Key and Rhea ID do not receive protected file contents.
The three lanes describe product responsibilities. They are different from the RED operating model, which describes how an organization currently uses RED with Rhea Key and its selected storage.
Separating data protection, authorization and identity reduces the amount of sensitive information any one Rhea product needs to handle. Rhea Key and Rhea ID do not receive protected file contents. A storage provider receives encrypted file content rather than readable protected content.
Data
RED
Protected file content is encrypted client-side with AES-256-GCM before it reaches connected object storage. Bring Your Own Storage — AWS S3 today.
Authorization
Rhea Key
Cryptographic authentication, signing and approval on the user's device. Does not receive or process protected file contents. Web and Android today; iOS coming soon.
Identity
Rhea ID
Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Not required for current RED operations.
Products
Three products. Three responsibilities.
RED
Enterprise data protection and management infrastructure. Protected file content is encrypted client-side before it reaches the organization's own storage — Bring Your Own Storage, starting with AWS S3.
Rhea Key
Cryptographic authentication, signing and approval on the user's device. Private authentication material remains protected by the device and is not transmitted to Rhea. Web and Android available; iOS coming soon.
Rhea ID
Coming soon. Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Rhea ID does not carry RED protected-file contents.
Availability
What is available today.
Today, RED supports human-controlled protected-file operations with organization-selected AWS S3 storage. Rhea's direction is to extend RED's protection, authorization and audit model to additional storage providers, supported databases, authorized applications and controlled agent workflows. Those integration interfaces are planned and are not currently generally available.
Outside these status tables, only limitations are labelled: an item shown without a status marker is generally available today.
Products and clients
| Product | Status | Meaning |
|---|---|---|
| REDStatus: AvailableEnterprise data protection and management infrastructure | Status: Available | Enterprise data protection and management infrastructure |
| Rhea Key WebStatus: AvailableCryptographic authentication, signing and approval | Status: Available | Cryptographic authentication, signing and approval |
| Rhea Key AndroidStatus: AvailableCryptographic authentication, signing and approval | Status: Available | Cryptographic authentication, signing and approval |
| Rhea Key iOSStatus: Coming soonPlanned iOS client | Status: Coming soon | Planned iOS client |
| Rhea IDStatus: Coming soonVerified identity or selected attributes | Status: Coming soon | Verified identity or selected attributes |
Not available today
- Public RED API or SDK documentation
- Generally available application integration
- Generally available agent integration
- BYOD and database integrations
- Multi-cloud object-storage support beyond AWS S3
- Rhea ID
- Rhea Key iOS
These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.
RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.
BYOS · Provider independence
Your data stays where you choose.
With BYOS, RED protects data in your own storage — without moving it into Rhea-owned infrastructure.
Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.
RED control infrastructure
Protect · Organize · Authorize · Access · Share · Move · Audit
Supported and planned storage
Amazon S3
Azure Blob Storage
Google Cloud Storage
Cloudflare R2
Oracle Cloud Object Storage
S3-compatible storage
RED separates its protection and authorization model from the storage provider. AWS S3 is supported today; broader provider portability depends on planned integrations.
BYOS
Bring Your Own Storage
Connect your organization's AWS S3 environment. Protected file content is encrypted client-side before it reaches the provider, and RED maintains the protection, authorization and audit model around it.
BYOD
Status: PlannedBring Your Own Database
Planned. Intended to extend RED's protection, authorization and audit model to supported database environments. Not currently generally available.
Planned data-environment support
Status: PlannedNamed environments indicate direction only. None is currently generally available.
Your data, your controlProtected before storageProvider-independent designAuditable by design
RED Pricing
Choose a plan based on your organization's data volume, usage, and deployment needs.
RED usage is based on the amount of data RED processes each month. This includes encryption, decryption and other processing performed by RED. VAT may apply. Plans are activated inside RED after organization setup.
All plans include client-side encryption and BYOS. RED offers a native 7-day trial — no card required to start a conversation.
Relay usage: In some situations, data may be processed through RED relay instead of the normal direct storage path. Only that portion is billed at the relay rate (10×).
Launch
LAUNCH€399
/ org / mo
€0.60
billed data (GiB)
- Client-side AES-256-GCM
- Bring Your Own Storage
- Access, permission and approval activity recorded.
Growth
GROWTH€1,499
/ org / mo
€0.15
billed data (GiB)
- Client-side AES-256-GCM
- Bring Your Own Storage
- Access, permission and approval activity recorded.
Expand
EXPAND€2,799
/ org / mo
€0.08
billed data (GiB)
- Client-side AES-256-GCM
- Bring Your Own Storage
- Access, permission and approval activity recorded.
Scale
SCALE€4,999
/ org / mo
€0.05
billed data (GiB)
- Client-side AES-256-GCM
- Bring Your Own Storage
- Access, permission and approval activity recorded.
Custom
ENTERPRISEVolume-based enterprise pricing
Talk to enterprise
- Dedicated onboarding
- Custom SLAs & regions
- Priority support
Estimate monthly usage
Pricing estimator
Estimate how much data RED will process each month to see your expected monthly cost.
All data RED encrypts, decrypts or otherwise processes for your organization.
Estimated monthly total
€1,799.00
on the Growth plan
- Operations
- 2,000 GiB
- Plan
- Growth
- Base fee
- €1,499.00
- Usage charge
- €300.00
- Estimated monthly total
- €1,799.00
This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside RED.
Trust & privacy
Protected before storage.
Client-side encryption
Protected file content is encrypted with AES-256-GCM on the user's device before it reaches connected object storage. Each protected document is encrypted with its own data-encryption key, wrapped for authorized recipients.
Non-custodial approvals
Rhea Key signs approvals on the user's device. Private authentication material remains protected by the device and is not transmitted to Rhea. Rhea does not operate a key-recovery service.
Audit & accountability
RED records access attempts, permission changes, approvals, organization administration, encryption and decryption operations, and relevant protected-document lifecycle events. Audit records contain operational metadata, not readable protected content.
Bring Your Own Storage
Your organization keeps ownership of the underlying AWS S3 environment. Only encrypted protected-file content reaches it; RED and Rhea still process the operational metadata required to provide authorization, administration, metering, security and audit functions.
No advertising, no scanning
RED does not sell customer data, build ad profiles, or scan protected content for advertising.
Identity kept minimal
Coming soon. Rhea ID is intended to let a service confirm a required identity fact or attribute without the user repeatedly distributing more personal information than the decision requires.
Where Rhea is going · Planned
Extending organizational control to every authorized actor.
Rhea's direction is to extend RED from human-controlled protected-file operations to supported databases, applications and controlled agent workflows. Planned interfaces are intended to let authorized systems request narrowly scoped operations under organizational policy, required human approval and audit.
Databases
Extend RED's protection, authorization and audit model to supported database environments.
Bring Your Own Database and every named database integration are planned and not currently generally available.
Applications
Allow authorized applications to request narrowly scoped operations through defined interfaces.
No public application-integration interface, API or SDK is available today.
Agents
Allow controlled agent workflows to request approved access without receiving unrestricted visibility into organizational data.
No agent integration surface is available today.
These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.
See architecture and direction
