RED — Rhea Encrypted Data

Enterprise data, readable only to the people who should read it.

RED is Rhea's enterprise data protection and management infrastructure — not an encrypted storage service. It sits above organization-selected data environments and governs how sensitive data is protected, organized, authorized, accessed, shared, moved and audited.

Category

What RED is — and what it is not.

RED is

  • Data protection and management infrastructure
  • An organizational command center for sensitive data
  • A separate protection and authorization model above supported storage
  • Infrastructure for protecting, organizing, accessing, sharing, moving and auditing sensitive data

RED is not

  • A conventional cloud drive
  • An encrypted-storage subscription
  • A replacement for AWS S3
  • Merely an encryption utility
  • Merely a key vault
  • A publicly available application or agent integration network today

RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.

Why RED exists

Storage access is not the same as data readability.

Cloud credentials and storage permissions determine who can reach stored objects. RED adds a separate protection and authorization model around sensitive file content. Possession of a protected object — whether reached through normal administration, copied storage credentials, or a storage incident — is not by itself sufficient to make that content readable.

Client-side encryption is one enforcement mechanism inside RED; RED's category is enterprise data protection and management infrastructure.

Who RED is for

RED is designed for organizations that need to keep sensitive information in their selected cloud environment while separating possession of stored objects from permission to make protected content readable.

  • Sensitive internal and operational documents
  • Financial, legal, client, regulatory, technical or strategic information
  • Protected sharing and controlled external file collection
  • Organization-controlled access and approval workflows

RED is not positioned as a replacement for collaboration suites, cloud storage, DLP, SIEM, KMS, secrets managers, data catalogs or databases.

Current capabilities

A single infrastructure for protected data operations.

Protect

Protected file content is encrypted client-side before it reaches connected storage.

Organize

Protected documents are organized inside the organization's RED workspace.

Authorize

Organizational permissions and signed approvals govern sensitive actions.

Access

Protected content becomes readable only through an authorized operation.

Share

Protected sharing and controlled external file collection under organizational permission.

Move

Movement of protected data within currently supported RED storage operations. Cross-provider movement depends on planned additional provider support.

Audit

Relevant operational metadata records the actor, action, resource, time and outcome where applicable.

Capability status

Capability status
CapabilityStatusMeaning
BYOS with AWS S3Status: AvailableOrganization-selected AWS S3 environment
Protected-file encryptionStatus: AvailableAES-256-GCM client-side before protected content reaches object storage
Organization rolesStatus: AvailableOwner / Admin / Member
Rhea Key approvalStatus: AvailableHuman authentication/signing on the user's device
Cross-provider movementStatus: PlannedRequires additional provider integrations
BYODStatus: PlannedNot currently generally available
Application/agent interfacesStatus: PlannedNo public integration surface claimed today

Current RED operating model

Authority above. Storage below. RED in between.

Organizational authority

Owner · Admin · Member

Organizational permissions govern who may request sensitive actions.

Human authorization

Rhea Key · Supported Trezor hardware

Authentication, signing and approval on the user's device.

RED control infrastructure

Protect · Organize · Authorize · Access · Share · Move · Audit

The protection, authorization and audit model around your data.

Organization-selected storage

AWS S3

The organization's own AWS S3 environment.

This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.

Data and trust boundary

What RED protects, and where the boundary sits.

Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.

If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.

Protected file content is encrypted with AES-256-GCM on the user's device before it reaches connected object storage.

Each protected document is encrypted with its own data-encryption key, which is wrapped for authorized recipients.

Deployment today

Organization-selected storage, starting with AWS S3.

Deployment status

Deployment status
Storage / environmentStatusMeaning
AWS S3 (BYOS)Status: AvailableOrganization-selected AWS S3 environment
Azure Blob StorageStatus: Planned
Google Cloud StorageStatus: Planned
Cloudflare R2Status: Planned
Oracle Cloud Object StorageStatus: Planned
S3-compatible storageStatus: PlannedBeyond the currently supported AWS S3 path
BYOD (Bring Your Own Database)Status: PlannedSupported database environments in the future

RED separates its protection and authorization model from the storage provider. AWS S3 is supported today; broader provider portability depends on planned integrations.

RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.

Not available today

  • Public RED API or SDK documentation
  • Generally available application integration
  • Generally available agent integration
  • BYOD and database integrations
  • Multi-cloud object-storage support beyond AWS S3
  • Rhea ID
  • Rhea Key iOS

These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.

Where Rhea is going · Planned

Extending organizational control to every authorized actor.

Rhea's direction is to extend RED from human-controlled protected-file operations to supported databases, applications and controlled agent workflows. Planned interfaces are intended to let authorized systems request narrowly scoped operations under organizational policy, required human approval and audit.

Status: Planned

Databases

Extend RED's protection, authorization and audit model to supported database environments.

Bring Your Own Database and every named database integration are planned and not currently generally available.

Status: Planned

Applications

Allow authorized applications to request narrowly scoped operations through defined interfaces.

No public application-integration interface, API or SDK is available today.

Status: Planned

Agents

Allow controlled agent workflows to request approved access without receiving unrestricted visibility into organizational data.

No agent integration surface is available today.

These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.

See architecture and direction

Start with a security review, pricing, or a deployment discussion.