RED
One environment for your organization's data.
RED protects data on the device before connected storage receives it, and keeps the authority to read it separate from the infrastructure holding it. Storage becomes a place to put objects, not a place that decides who can read them.
Maturity
What RED is today
RED is generally available. AWS S3 is the approved public storage path; every other environment carries its own status.
Organizations use RED to hold protected documents and secrets, request sensitive files from outside parties, share access with named members, apply approvals to sensitive actions, and produce evidence of what happened.
The workspace
Where the sensitive material lives.
Documents and human-managed secrets, protected on the device before storage.
Protected documents
Organize sensitive files in a document vault with folders, search, filters and per-item actions.
The organization keeps one place for the files it cannot afford to lose control of.
Evidence Access, sharing and lifecycle events are recorded.
Read moreClient-side protection
File contents are encrypted on the device with AES-256-GCM before connected storage receives them.
Storage receives protected objects, not readable content.
RED does not protect plaintext after an authorized decryption, and cannot eliminate risk on a compromised authorized endpoint.
Read moreSecure Notes
Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows.
Secrets stop living in chat messages, spreadsheets and personal note apps.
Evidence Creation, access and sharing of a note are recorded.
Secure Notes serve human-managed secrets. They are not a machine-secrets manager for application runtime injection.
Read moreEncrypted filename and folder metadata
Protect names and structure in addition to contents.
Removes the most significant remaining metadata exposure.
Exchange
Getting data in and out under control.
Collection and sharing stay inside the organization's protection model.
Secure File Requests
Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links.
Inbound sensitive material enters the organization's protection model at the point of collection.
Evidence Request creation, submission and receipt are recorded.
Read moreShared Access Control
Share protected folders and files with defined members and keep the organization's access model intact.
Sharing does not mean handing out a link that outlives the relationship.
Evidence Member additions, removals and file access are recorded.
Read moreSecurity operations
Running protection as an operation, not an assumption.
Access and approvals
Apply roles and permissions, and require Rhea Key approval for sensitive actions.
Authority to read is a decision the organization makes, not a side effect of infrastructure access.
Evidence Authorization decisions and approvals are recorded.
Read moreEncryption health
Review protection coverage, key versions, and re-wrapping state across the organization's documents.
Protection state becomes an operational metric instead of an assumption.
Read moreSessions and security alerts
Review active sessions and security alerts, and end sessions when required.
Access that is no longer appropriate can be ended immediately.
Read moreGuardian key recovery
Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent.
Continuity does not require Rhea to hold a copy of the organization's authority.
If a guardian loses both their Recovery Kit and its passphrase, that guardian's share is permanently lost.
Read moreRetention and archive
Configure retention, archive documents, and control trash behavior.
Sensitive material has a defined end of life.
Read moreClassification
Classify documents so that policy and review can operate on sensitivity, not only on location.
Controls follow the sensitivity of the information.
Infrastructure
Your storage. Your account. Your control.
RED connects to storage the organization already owns and operates.
AWS S3 connection (Bring Your Own Storage)
Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from RED.
The organization keeps ownership of the storage account holding its protected objects.
Read moreCross-storage move
Select protected data, choose another connected destination, and move it — with RED handling checking, transfer, verification, cutover, cleanup and audit.
Infrastructure can change without the organization abandoning its protection and evidence model.
Today, moving between storage locations copies the data. The source object is not deleted by the move itself.
Read moreDatabase connections (BYOD)
Extend the same protection, authorization and audit model to connected databases.
Structured data faces the same control problem as documents.
RED API and SDK
Defined interfaces for applications to operate against protected data under scoped authority.
Applications become authorized actors instead of exceptions.
Category
What RED is not.
RED is enterprise data protection and management infrastructure. It is deliberately none of the following.
- Encrypted storage
- A secure file-sharing service
- File encryption software
- Backup software
- Multi-cloud storage
- A cloud replacement
Administration
Members, roles and evidence.
Organization administration
Manage members and roles, review usage and system health, and configure the organization.
One control surface for the people and settings around protected data.
Read moreAudit and evidence
Review access, approval, administrative and security events, and verify the hash chain over cryptographic events.
The organization can show what happened, not only assert it.
The hash chain covers cryptographic and key-management events. It is not a claim that every record of every type is immutable.
Read moreRED pricing
Priced on the data RED processes, not on the storage you own.
RED usage is based on the amount of data RED processes each month, including encryption, decryption and related processing. VAT may apply. Plans are activated inside RED after organization setup.
All plans include encryption on the device before storage and Bring Your Own Storage. RED offers a native 7-day trial.
Relay usage: in some situations, data is processed through RED relay instead of the direct storage path. Only that portion is billed at the relay rate (10×).
Launch
€399
/ org / mo
€0.60
billed data (GiB)
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Growth
€1,499
/ org / mo
€0.15
billed data (GiB)
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Expand
€2,799
/ org / mo
€0.08
billed data (GiB)
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Scale
€4,999
/ org / mo
€0.05
billed data (GiB)
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Custom
Volume-based enterprise pricing
- Dedicated onboarding
- Custom SLAs and regions
- Priority support
Estimate monthly usage
Pricing estimator
Estimate how much data RED will process each month to see your expected monthly cost.
All data RED encrypts, decrypts or otherwise processes for your organization.
Estimated monthly total
€1,799.00
on the Growth plan
- Operations
- 2,000 GiB
- Plan
- Growth
- Base fee
- €1,499.00
- Usage charge
- €300.00
- Estimated monthly total
- €1,799.00
This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside RED.
See it against your own environment.
Connect your own storage, protect a document, and read the recorded evidence yourself.