Protect
Content is encrypted on the device with a key the institution controls, before it reaches any provider.
Rhea Data
Rhea Data brings protected documents, permissions and data workflows into one environment. Connect supported storage, organize information, control sharing and collection, move protected documents and review recorded activity. File content is encrypted on the device before it reaches storage.
The seven operations
Rhea Data does not add another place to put files. It governs the seven things that actually happen to information, wherever that information already lives.
Content is encrypted on the device with a key the institution controls, before it reaches any provider.
A catalog of every protected object and record across every connected estate, with classification, placement policy and search.
Policy decides whether an operation may run; a customer-held key proves the authority to run it. Sensitive operations require quorum.
Content becomes readable only through an authorised, short-lived, single-use release, evaluated fail-closed.
Protected sharing inside and outside the institution, and controlled inbound collection, without handing out links that outlive the relationship.
Movement between locations and across providers as one governed operation, verified at the destination.
Every operation writes a hash-chained record of actor, action, resource, time and outcome, verifiable offline.
One authority model.
The same key, the same policy evaluation and the same evidence chain apply to all seven, across every connected estate.
Zero Custody architecture
The asymmetry is deliberate. Authority is manufactured on the institution’s side of the boundary, and execution happens there too. Rhea holds the workflow, the policy decision and the evidence — never the keys that make data readable.
A person or an executive quorum signs the request on their own device with Rhea Key. The private key never leaves it.
Holds: Private signing key
Rhea evaluates policy, sequences the operation and records it. It carries a signed instruction, not a credential.
Holds: Ciphertext and metadata
A connector inside the customer's own network holds every provider credential and every decryption key, and performs the operation.
Holds: Provider credentials · decryption keys
Object storage and relational estates the institution already owns. Nothing is migrated and nothing is copied to Rhea.
Holds: The data itself
Five planes
Execution modes
Rhea operates the execution path. Content is still encrypted on the device before it reaches storage, so Rhea handles ciphertext and metadata.
Fast onboarding for regulated mid-market teams.
Storage credentials are sealed on the customer's own device and opened only in browser memory. Rhea holds an envelope it has no key for, and signed requests go straight from the browser to the customer's storage account.
Organisations that cannot let a vendor hold cloud credentials.
A connector inside the customer's VPC holds every provider credential and every decryption key. Rhea coordinates the workflow and is cryptographically blinded to its contents.
Central banks, governments and sovereign defence.
Bring your own storage
Institutions connect the object storage and relational estates they already operate. There is no migration programme, no second copy of the data, and no dependency that makes leaving expensive.
Customer-owned buckets
Customer-owned, connected in place
Customer-owned, connected in place
Customer-owned, connected in place
Customer-owned, connected in place
Customer-owned, connected in place
Customer-owned, connected in place
Governed in place, no migration
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Maturity
Rhea Data governs data across customer-owned object storage and relational estates. Organisations connect the infrastructure they already run — AWS, Azure, Google Cloud, Oracle, Cloudflare, MinIO, on-premises — without migrating anything.
Use Rhea Data to organize protected documents and Secure Notes, request files from outside parties, share with defined members, approve sensitive actions and review what happened. The Command Center brings operational usage and organizational visibility together.
Ownership
Rhea Data is for organizations that need important information to remain protected and usable across teams, with controlled access, customer-owned storage and recorded activity. Security and infrastructure teams configure the environment; business teams use it for everyday data work.
LimitationRhea Data serves human-controlled organizational file workflows today. Application authority, AI-agent authority, database connectivity and public integration interfaces are Planned.
Data operations
Documents and Secure Notes, organized for the people authorized to use them.
Organize sensitive files in a document vault with folders, search, filters and per-item actions.
The organization keeps one place for the files it cannot afford to lose control of.
Evidence Access, sharing and lifecycle events are recorded.
Read moreFile contents are encrypted on the device with AES-256-GCM before connected storage receives them.
Storage receives protected objects, not readable content.
Rhea Data does not protect plaintext after an authorized decryption, and cannot eliminate risk on a compromised authorized endpoint.
Read moreKeep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows.
Secrets stop living in chat messages, spreadsheets and personal note apps.
Evidence Creation, access and sharing of a note are recorded.
Secure Notes serve human-managed secrets. They are not a machine-secrets manager for application runtime injection.
Read moreProtect filenames and folder structure in addition to contents.
Closes the most significant remaining metadata exposure.
Exchange
Collection and sharing stay inside the organization's protection model.
Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links.
Inbound sensitive material enters the organization's protection model at the point of collection.
Evidence Request creation, submission and receipt are recorded.
Read moreShare protected folders and files with defined members and keep the organization's access model intact.
Sharing does not mean handing out a link that outlives the relationship.
Evidence Member additions, removals and file access are recorded.
Read moreSecurity operations
Apply roles and permissions, and require Rhea Key approval for sensitive actions.
Authority to read is a decision the organization makes, not a side effect of infrastructure access.
Evidence Authorization decisions and approvals are recorded.
Read moreReview protection coverage, key versions, and re-wrapping state across the organization's documents.
Protection state becomes an operational metric instead of an assumption.
Read moreReview active sessions and security alerts, and end sessions when required.
Access that is no longer appropriate can be ended immediately.
Read moreRecover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent.
Continuity does not require Rhea to hold a copy of the organization's authority.
If a guardian loses both their Recovery Kit and its passphrase, that guardian's share is permanently lost.
Read moreConfigure retention, archive documents, and control trash behavior.
Sensitive material has a defined end of life.
Read moreClassify documents so that policy and review operate on sensitivity, not only on location.
Controls follow the sensitivity of the information.
Infrastructure
Rhea Data connects to storage the organization already owns and operates.
Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from Rhea Data.
The organization keeps ownership of the storage account holding its protected objects.
Read moreMove protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by Rhea Data.
Storage layout can change without the organization abandoning its protection and evidence model.
A move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation.
Read moreMove protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation.
Changing provider becomes an operation rather than a migration project.
Read moreGovern relational estates in place under scoped authority, starting with PostgreSQL. The database stays where it is; no migration is required.
Structured data faces the same control problem as documents, and answers to the same authority model.
Interfaces for approved applications to request supported data operations under bounded, expiring authority.
Applications become authorised actors instead of standing exceptions with permanent tokens.
Category
Rhea Data combines data workflows, protection, permissions and recorded activity. These responsibilities explain its role:
Administration
Manage members and roles, review usage and system health, and configure the organization.
One control surface for the people and settings around protected data.
Read moreReview access, approval, administrative and security events, and verify the hash chain over cryptographic events.
The organization can show what happened, not only assert it.
The hash chain covers cryptographic and key-management events. It is not a claim that every record of every type is immutable.
Read moreRhea Data pricing
Rhea Data usage is based on the amount of data Rhea Data processes each month, including encryption, decryption and related processing. VAT may apply. Plans are activated inside Rhea Data after organization setup.
All plans include encryption on the device before storage and Bring Your Own Storage. Rhea Data offers a native 7-day trial.
€399
/ organization / month
€0.60
/ GiB processed
€1,499
/ organization / month
€0.15
/ GiB processed
€2,799
/ organization / month
€0.08
/ GiB processed
€4,999
/ organization / month
€0.05
/ GiB processed
For requirements outside the standard plans.
Estimate monthly usage
Enter the data Rhea Data processes each month and the number of operations. The cheapest standard plan is selected for you.
Everything Rhea Data encrypts, decrypts or otherwise processes for your organization.
Data that goes through the Rhea Data relay instead of the direct storage path. This portion is billed once, at 10× the plan rate.
Counted per request, metered at €0.01 per 1,000 operations.
Estimated monthly total
€1,601.50
on the Launch plan (cheapest at this usage)
Relay-processed data is charged once, at the relay rate only. This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside Rhea Data.
Explore Rhea Data, connect supported customer-owned storage and work through a document workflow. Review permissions and recorded activity in the same environment.