Architecture and direction

Three products. One security architecture.

RED is enterprise data protection and management infrastructure. Rhea Key provides cryptographic authentication and human approval. Rhea ID is planned to establish verified identity or attributes. Rhea Key and Rhea ID do not receive protected file contents.

Current product responsibilities

01

Data

RED

Protected file content is encrypted client-side with AES-256-GCM before it reaches connected object storage. Bring Your Own Storage — AWS S3 today. RED maintains the protection, authorization and audit model around those operations.

02

Authorization

Rhea Key

Cryptographic authentication, signing and approval on the user's device. Rhea Key does not receive or process the content of protected files. Web and Android are available; iOS is coming soon.

03Status: Coming soon

Identity

Rhea ID

Planned to establish verified identity — or specific identity attributes — for services that choose to require them. Rhea ID does not carry RED protected-file contents and is not required for current RED operations.

The three lanes describe product responsibilities. They are different from the RED operating model, which describes how an organization currently uses RED with Rhea Key and its selected storage.

Current RED operating model

Authority above. Storage below. RED in between.

Organizational authority

Owner · Admin · Member

Organizational permissions govern who may request sensitive actions.

Human authorization

Rhea Key · Supported Trezor hardware

Authentication, signing and approval on the user's device.

RED control infrastructure

Protect · Organize · Authorize · Access · Share · Move · Audit

The protection, authorization and audit model around your data.

Organization-selected storage

AWS S3

The organization's own AWS S3 environment.

This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.

What separation achieves

Separation is a security property, not a convention.

Separating data protection, authorization and identity reduces the amount of sensitive information any one Rhea product needs to handle. Rhea Key and Rhea ID do not receive protected file contents. A storage provider receives encrypted file content rather than readable protected content.

Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.

If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.

The red horizon is the boundary between readable data — under the organization's control — and the infrastructure that holds protected objects.

Planned operating model

Future controlled-use model.

This model shows how Rhea intends to extend control beyond human access. Nodes shown without a status marker are available today; every other node is labelled individually with its own status.

Actors and requesters

  • People — current RED / Rhea Key workflows

    Status: Available
  • Applications

    Status: Planned
  • Agents

    Status: Planned

Trust and authorization

  • Rhea Key human authentication and approval

    Status: Available
  • Rhea ID verified identity / attributes

    Status: Coming soon
  • External-system / scoped authorization interfaces

    Status: Planned

RED

  • Current RED protected-data control functions

    Status: Available
  • Generalized external request / policy interfaces

    Status: Planned

Data environments

  • AWS S3 object storage

    Status: Available
  • Additional object storage

    Status: Planned
  • Databases and data environments

    Status: Planned

The solid path represents currently available RED operations. Dashed paths represent Rhea's intended direction and are not currently generally available.

Illustrative future request lifecycle · Planned

How a scoped request is intended to work.

  1. 01An authorized application or agent requests a narrowly scoped operation.
  2. 02Its future integration authority and requested scope are evaluated.
  3. 03RED applies the organization's intended policy and permission requirements.
  4. 04Human approval through Rhea Key may be required for sensitive actions.
  5. 05Rhea ID may provide a required verified identity attribute when the organization chooses to require one.
  6. 06Only the approved operation is intended to proceed.
  7. 07Relevant request, decision, action, resource, time and outcome metadata is intended to be recorded.
  8. 08Data remains in the organization-selected supported environment.

This describes product direction, not a generally available public integration interface. Exact technical behavior will be documented when the corresponding surfaces are released.

Direction matrix

Every direction, with its current status.

Today, RED supports human-controlled protected-file operations with organization-selected AWS S3 storage. Rhea's direction is to extend RED's protection, authorization and audit model to additional storage providers, supported databases, authorized applications and controlled agent workflows. Those integration interfaces are planned and are not currently generally available.

Status: AvailableGenerally available today.Status: Coming soonIn development, not yet available.Status: PlannedProduct direction, not currently generally available.

Outside these status tables, only limitations are labelled: an item shown without a status marker is generally available today.

Rhea direction matrix with availability status
DirectionStatus
AWS S3 BYOSCurrent connected object-storage pathStatus: Available
Additional object storesBroader provider supportStatus: Planned
BYODSupported database environments in the futureStatus: Planned
ApplicationsNarrowly scoped requests through defined interfacesStatus: Planned
AgentsControlled workflows without unrestricted data visibilityStatus: Planned
Rhea IDVerified identity or selected attributesStatus: Coming soon
Rhea Key iOSPlanned iOS clientStatus: Coming soon

Rhea is building infrastructure for keeping organizational data under controlled use across storage environments, databases, people, applications and agents. RED governs how protected data is accessed and used. Rhea Key provides cryptographic authentication and human approval. Rhea ID is planned to establish verified identity or specific attributes when required. Organizations retain control of their data environments, policies and authorized actors.