Rhea Data

One environment for your organization's data.

Rhea Data brings protected documents, permissions and data workflows into one environment. Connect supported storage, organize information, control sharing and collection, move protected documents and review recorded activity. File content is encrypted on the device before it reaches storage.

The seven operations

Everything an institution does to data, governed as one model.

Rhea Data does not add another place to put files. It governs the seven things that actually happen to information, wherever that information already lives.

01

Protect

Content is encrypted on the device with a key the institution controls, before it reaches any provider.

02

Organise

A catalog of every protected object and record across every connected estate, with classification, placement policy and search.

03

Authorise

Policy decides whether an operation may run; a customer-held key proves the authority to run it. Sensitive operations require quorum.

04

Access

Content becomes readable only through an authorised, short-lived, single-use release, evaluated fail-closed.

05

Share

Protected sharing inside and outside the institution, and controlled inbound collection, without handing out links that outlive the relationship.

06

Move

Movement between locations and across providers as one governed operation, verified at the destination.

07

Audit

Every operation writes a hash-chained record of actor, action, resource, time and outcome, verifiable offline.

One authority model.

The same key, the same policy evaluation and the same evidence chain apply to all seven, across every connected estate.

Zero Custody architecture

Rhea coordinates the operation and cannot perform it alone.

The asymmetry is deliberate. Authority is manufactured on the institution’s side of the boundary, and execution happens there too. Rhea holds the workflow, the policy decision and the evidence — never the keys that make data readable.

Institution

Holder key

A person or an executive quorum signs the request on their own device with Rhea Key. The private key never leaves it.

Holds: Private signing key

Rhea

Coordination

Rhea evaluates policy, sequences the operation and records it. It carries a signed instruction, not a credential.

Holds: Ciphertext and metadata

Institution

Connector in your VPC

A connector inside the customer's own network holds every provider credential and every decryption key, and performs the operation.

Holds: Provider credentials · decryption keys

Institution

Your storage and databases

Object storage and relational estates the institution already owns. Nothing is migrated and nothing is copied to Rhea.

Holds: The data itself

Plaintext exists only inside the institution’s own environment. Compromising Rhea yields a workflow and a ledger, not a readable file, because the material needed to decrypt it was never on this side of the boundary.

Five planes

One architecture, five separated responsibilities.

Authority
Who may act. Keys held by people and executive quorums, delegations held by machines, all revocable and all expiring.
Catalog
What exists. Every protected object and governed record across every connected provider and database, classified and placed by policy.
Policy
What is permitted. Rules evaluated fail-closed: if policy cannot be read, the operation is denied rather than allowed.
Execution
What actually runs. Standard, Hardened or Zero Custody — in the strongest mode, entirely inside the customer's own VPC.
Evidence
What can be proven. A hash-chained ledger where each entry commits to the last, so retroactive edits break verification.

Execution modes

Choose how much Rhea is allowed to touch.

Standard

Rhea operates the execution path. Content is still encrypted on the device before it reaches storage, so Rhea handles ciphertext and metadata.

Fast onboarding for regulated mid-market teams.

Hardened

Storage credentials are sealed on the customer's own device and opened only in browser memory. Rhea holds an envelope it has no key for, and signed requests go straight from the browser to the customer's storage account.

Organisations that cannot let a vendor hold cloud credentials.

Zero Custody

A connector inside the customer's VPC holds every provider credential and every decryption key. Rhea coordinates the workflow and is cryptographically blinded to its contents.

Central banks, governments and sovereign defence.

Bring your own storage

Your estate stays yours. Rhea never becomes the storage.

Institutions connect the object storage and relational estates they already operate. There is no migration programme, no second copy of the data, and no dependency that makes leaving expensive.

AWS S3

Customer-owned buckets

MinIO / S3-compatible

Customer-owned, connected in place

Microsoft Azure Blob Storage

Customer-owned, connected in place

Google Cloud Storage

Customer-owned, connected in place

Oracle Cloud Object Storage

Customer-owned, connected in place

Cloudflare R2

Customer-owned, connected in place

Private and on-premises infrastructure

Customer-owned, connected in place

Databases (PostgreSQL and supported relational estates)

Governed in place, no migration

Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.

Maturity

What Rhea Data is today

Rhea Data governs data across customer-owned object storage and relational estates. Organisations connect the infrastructure they already run — AWS, Azure, Google Cloud, Oracle, Cloudflare, MinIO, on-premises — without migrating anything.

Use Rhea Data to organize protected documents and Secure Notes, request files from outside parties, share with defined members, approve sensitive actions and review what happened. The Command Center brings operational usage and organizational visibility together.

Ownership

Who deploys and uses Rhea Data.

Rhea Data is for organizations that need important information to remain protected and usable across teams, with controlled access, customer-owned storage and recorded activity. Security and infrastructure teams configure the environment; business teams use it for everyday data work.

  • Sponsored by: Security, technology, data-protection or operational leadership.
  • Operated by: Security, platform, cloud or data-infrastructure teams.
  • Used by: Teams handling important organizational files.
  • Extended to: Clients, partners and contractors through controlled sharing and collection.

LimitationRhea Data serves human-controlled organizational file workflows today. Application authority, AI-agent authority, database connectivity and public integration interfaces are Planned.

Infrastructure

Your storage. Your account. Your control.

Rhea Data connects to storage the organization already owns and operates.

Category

How Rhea Data fits into your stack.

Rhea Data combines data workflows, protection, permissions and recorded activity. These responsibilities explain its role:

  • Your connected provider continues to hold the stored data.
  • Rhea Data provides the environment for supported data operations.
  • Encryption protects file content before storage.
  • Rhea Key supports authentication and approvals.
  • Your existing identity and security controls still matter.
  • In Zero Custody mode, execution credentials and decryption keys never leave your own environment.

Rhea Data pricing

Priced on the data Rhea Data processes, not on the storage you own.

Rhea Data usage is based on the amount of data Rhea Data processes each month, including encryption, decryption and related processing. VAT may apply. Plans are activated inside Rhea Data after organization setup.

All plans include encryption on the device before storage and Bring Your Own Storage. Rhea Data offers a native 7-day trial.

  • Operations are billed at €0.01 per 1,000 operations.
  • Only relay-processed data is charged at 10× the selected plan's data rate. The relay portion is charged once, not at both the standard and relay rate.
  • Customer-owned storage-provider charges are separate and paid directly by the customer.

Launch

€399

/ organization / month

€0.60

/ GiB processed

  • Encryption on the device before storage
  • Bring Your Own Storage
  • Access, permission and approval activity recorded
View plan in Rhea Data

Growth

€1,499

/ organization / month

€0.15

/ GiB processed

  • Encryption on the device before storage
  • Bring Your Own Storage
  • Access, permission and approval activity recorded
View plan in Rhea Data

Expand

€2,799

/ organization / month

€0.08

/ GiB processed

  • Encryption on the device before storage
  • Bring Your Own Storage
  • Access, permission and approval activity recorded
View plan in Rhea Data

Scale

€4,999

/ organization / month

€0.05

/ GiB processed

  • Encryption on the device before storage
  • Bring Your Own Storage
  • Access, permission and approval activity recorded
View plan in Rhea Data

Custom

For requirements outside the standard plans.

Contact Rhea

Estimate monthly usage

Pricing estimator

Enter the data Rhea Data processes each month and the number of operations. The cheapest standard plan is selected for you.

GiB

Everything Rhea Data encrypts, decrypts or otherwise processes for your organization.

GiB

Data that goes through the Rhea Data relay instead of the direct storage path. This portion is billed once, at 10× the plan rate.

ops

Counted per request, metered at €0.01 per 1,000 operations.

Estimated monthly total

€1,601.50

on the Launch plan (cheapest at this usage)

Base fee
€399
Direct data — 2,000 GiB
€1,200
Relay data — 0 GiB at 10×
€0
Operations — 250,000
€2.50
Estimated monthly total
€1,601.50

Relay-processed data is charged once, at the relay rate only. This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside Rhea Data.

Start inside Rhea Data.

Explore Rhea Data, connect supported customer-owned storage and work through a document workflow. Review permissions and recorded activity in the same environment.