Support · FAQs
Frequently asked questions.
Straight answers about RED, Rhea Key, Rhea ID, current availability, data protection, authorization, deployment, billing, and Rhea's planned integration direction.
BYOS · AWS S3 availableBYOD · Planned
01 · RED & storage
RED & storage.
What RED is, what is available today, and where customer data and metadata actually live.
Is RED a storage service?
No. Your connected storage provider holds the stored data. RED (RheaData) is the environment for protected documents, permissions, sharing, collection, supported movement and recorded activity. Rhea's broader direction is a reusable authority and operations layer across supported systems.
What is available today?
RED's current public storage path is customer-owned AWS S3. Current document workflows include protection, organization, sharing, file requests, supported S3 movement and recorded activity. The Product Status page distinguishes these from controlled pilots, development work and planned expansion.
Where does customer data live?
RED-protected file content is stored as ciphertext in connected customer-owned storage. Rhea processes operational metadata and wrapped key material, and current connection modes can use provider credentials processed by its backend. Authorized devices handle readable content. The metadata and credentials page explains these boundaries.
What does the storage provider receive?
Only encrypted protected-file content and the object metadata needed to store it, such as object keys, sizes and access times. The storage provider does not receive plaintext or encryption keys.
What metadata does Rhea process?
RED and Rhea may process the operational metadata required to provide authorization, organization administration, metering, security and audit functions — for example organization structure, roles, sessions, document identifiers, storage references, usage records, and audit events. This operational metadata is distinct from protected file content and does not include the plaintext of anything stored.
What is BYOS?
Bring Your Own Storage (BYOS) means encrypted objects are written to a storage bucket the organization owns and controls rather than to a Rhea-hosted store. RED encrypts each object client-side with AES-256-GCM, then uploads the ciphertext. AWS S3 is generally available today. MinIO and S3-compatible storage, Microsoft Azure Blob Storage and Google Cloud Storage are in controlled pilot. Cloudflare R2, Oracle Object Storage and private or on-premises deployments are planned.
Is BYOD available?
Database connectivity is planned, starting with PostgreSQL. The direction is scoped database operations enforced in the customer's environment. This is not a claim that RED currently supports production database queries or arbitrary querying over encrypted data.
02 · Applications, agents & integrations
Applications, agents & integrations.
What today's workflow covers, and what Rhea's planned integration direction looks like.
Are applications or agents integrated today?
The new application, AI-agent and workload authority model is planned. It will let separately authorized software request supported operations under the same underlying model people use through RED. Each actor needs its own bounded authority; connecting an application will not automatically grant access to all organizational data.
Does RED provide a public API, SDK or MCP interface today?
Public interfaces for this architecture are planned. The aim is to let applications and agents use supported data operations without rebuilding the entire connection and authority model for each workflow. Existing internal endpoints are not a released public integration contract.
03 · Rhea Key & Rhea ID
Rhea Key & Rhea ID.
What Rhea Key authorizes today, what happens if a device is lost, and what Rhea ID is.
What does Rhea Key authorize?
Rhea Key authenticates the user and signs approvals in supported Rhea workflows. RED's organizational and resource permissions still determine what is allowed. Possessing or connecting a key does not grant universal access to an organization's data.
What happens if a device or key is lost?
Because private authentication material stays on the user's device and Rhea does not operate a key-recovery service, losing the device without a working recovery path can make data whose access depended only on that device's key unrecoverable through it. A lost or compromised device should be reset from another trusted device or reported so its authority can be invalidated for future authorizations.
What is Rhea ID, and is it required for RED?
Rhea ID is in development for verified identity attributes that can inform authorization decisions. It is separate from Rhea Key's cryptographic authentication. It is not a prerequisite for RED's current supported workflows.
04 · Billing & metering
Billing & metering.
How RED usage is measured and when the relay rate applies.
How is RED usage measured?
RED usage is based on the amount of data RED processes each month. This includes encryption, decryption and other processing performed by RED.
When does the 10× relay rate apply?
In some situations, data may be processed through RED relay instead of the normal direct storage path. Only that portion is billed at the relay rate (10×); everything else is billed at the normal rate. The pricing calculator on Pricing can model this.
05 · Compliance & storage model
Compliance & storage model.
What RED does and does not do for regulatory compliance, and how storage works.
Does RED make an organization compliant?
No. Organizations operating under GDPR, NIS2, DORA, EHDS or sector-specific requirements may evaluate RED as one technical and organizational control within a broader compliance programme. RED does not by itself make an organization compliant, and legal obligations depend on the organization's deployment, policies, processes, contracts and applicable law.
Does Rhea provide storage?
No. RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.
Support and security