Architecture and direction
Three products. One security architecture.
RED is enterprise data protection and management infrastructure. Rhea Key provides cryptographic authentication and human approval. Rhea ID is planned to establish verified identity or attributes. Rhea Key and Rhea ID do not receive protected file contents.
Current product responsibilities
Data
RED
Protected file content is encrypted client-side with AES-256-GCM before it reaches connected object storage. Bring Your Own Storage — AWS S3 today. RED maintains the protection, authorization and audit model around those operations.
Authorization
Rhea Key
Cryptographic authentication, signing and approval on the user's device. Rhea Key does not receive or process the content of protected files. Web and Android are available; iOS is coming soon.
Identity
Rhea ID
Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Rhea ID does not carry RED protected-file contents and is not required for current RED operations.
The three lanes describe product responsibilities. They are different from the RED operating model, which describes how an organization currently uses RED with Rhea Key and its selected storage.
Current RED operating model
Authority above. Storage below. RED in between.
Organizational authority
Owner · Admin · Member
Organizational permissions govern who may request sensitive actions.
Human authorization
Rhea Key · Supported Trezor hardware
Authentication, signing and approval on the user's device.
RED control infrastructure
Protect · Organize · Authorize · Access · Share · Move · Audit
The protection, authorization and audit model around your data.
Organization-selected storage
AWS S3
The organization's own AWS S3 environment.
This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.
What separation achieves
Separation is a security property, not a convention.
Separating data protection, authorization and identity reduces the amount of sensitive information any one Rhea product needs to handle. Rhea Key and Rhea ID do not receive protected file contents. A storage provider receives encrypted file content rather than readable protected content.
Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.
If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.
The red horizon is the boundary between readable data — under the organization's control — and the infrastructure that holds protected objects.
Planned operating model
Future controlled-use model.
This model shows how Rhea intends to extend control beyond human access. Nodes shown without a status marker are available today; every other node is labelled individually with its own status.
Actors and requesters
People — current RED / Rhea Key workflows
Status: AvailableApplications
Status: PlannedAgents
Status: Planned
Trust and authorization
Rhea Key human authentication and approval
Status: AvailableRhea ID verified identity / attributes
Status: Coming soonExternal-system / scoped authorization interfaces
Status: Planned
RED
Current RED protected-data control functions
Status: AvailableGeneralized external request / policy interfaces
Status: Planned
Data environments
AWS S3 object storage
Status: AvailableAdditional object storage
Status: PlannedDatabases and data environments
Status: Planned
The solid path represents currently available RED operations. Dashed paths represent Rhea's intended direction and are not currently generally available.
Illustrative future request lifecycle · Planned
How a scoped request is intended to work.
- 01An authorized application or agent requests a narrowly scoped operation.
- 02Its future integration authority and requested scope are evaluated.
- 03RED applies the organization's intended policy and permission requirements.
- 04Human approval through Rhea Key may be required for sensitive actions.
- 05Rhea ID may provide a required verified identity attribute when the organization chooses to require one.
- 06Only the approved operation is intended to proceed.
- 07Relevant request, decision, action, resource, time and outcome metadata is intended to be recorded.
- 08Data remains in the organization-selected supported environment.
This describes product direction, not a generally available public integration interface. Exact technical behavior will be documented when the corresponding surfaces are released.
Direction matrix
Every direction, with its current status.
Today, RED supports human-controlled protected-file operations with organization-selected AWS S3 storage. Rhea's direction is to extend RED's protection, authorization and audit model to additional storage providers, supported databases, authorized applications and controlled agent workflows. Those integration interfaces are planned and are not currently generally available.
Outside these status tables, only limitations are labelled: an item shown without a status marker is generally available today.
| Direction | Status | |
|---|---|---|
| AWS S3 BYOSCurrent connected object-storage path | Status: Available | Current connected object-storage path |
| Additional object storesBroader provider support | Status: Planned | Broader provider support |
| BYODSupported database environments in the future | Status: Planned | Supported database environments in the future |
| ApplicationsNarrowly scoped requests through defined interfaces | Status: Planned | Narrowly scoped requests through defined interfaces |
| AgentsControlled workflows without unrestricted data visibility | Status: Planned | Controlled workflows without unrestricted data visibility |
| Rhea IDVerified identity or selected attributes | Status: Coming soon | Verified identity or selected attributes |
| Rhea Key iOSPlanned iOS client | Status: Coming soon | Planned iOS client |
Rhea is building infrastructure for keeping organizational data under controlled use across storage environments, databases, people, applications and agents. RED governs how protected data is accessed and used. Rhea Key provides cryptographic authentication and human approval. Rhea ID is planned to establish verified identity or specific attributes when required. Organizations retain control of their data environments, policies and authorized actors.