RED — Rhea Encrypted Data
Enterprise data, readable only to the people who should read it.
RED is Rhea's enterprise data protection and management infrastructure — not an encrypted storage service. It sits above organization-selected data environments and governs how sensitive data is protected, organized, authorized, accessed, shared, moved and audited.
Category
What RED is — and what it is not.
RED is
- Data protection and management infrastructure
- An organizational command center for sensitive data
- A separate protection and authorization model above supported storage
- Infrastructure for protecting, organizing, accessing, sharing, moving and auditing sensitive data
RED is not
- A conventional cloud drive
- An encrypted-storage subscription
- A replacement for AWS S3
- Merely an encryption utility
- Merely a key vault
- A publicly available application or agent integration network today
RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.
Why RED exists
Storage access is not the same as data readability.
Cloud credentials and storage permissions determine who can reach stored objects. RED adds a separate protection and authorization model around sensitive file content. Possession of a protected object — whether reached through normal administration, copied storage credentials, or a storage incident — is not by itself sufficient to make that content readable.
Client-side encryption is one enforcement mechanism inside RED; RED's category is enterprise data protection and management infrastructure.
Who RED is for
RED is designed for organizations that need to keep sensitive information in their selected cloud environment while separating possession of stored objects from permission to make protected content readable.
- Sensitive internal and operational documents
- Financial, legal, client, regulatory, technical or strategic information
- Protected sharing and controlled external file collection
- Organization-controlled access and approval workflows
RED is not positioned as a replacement for collaboration suites, cloud storage, DLP, SIEM, KMS, secrets managers, data catalogs or databases.
Current capabilities
A single infrastructure for protected data operations.
Protect
Protected file content is encrypted client-side before it reaches connected storage.
Organize
Protected documents are organized inside the organization's RED workspace.
Authorize
Organizational permissions and signed approvals govern sensitive actions.
Access
Protected content becomes readable only through an authorized operation.
Share
Protected sharing and controlled external file collection under organizational permission.
Move
Movement of protected data within currently supported RED storage operations. Cross-provider movement depends on planned additional provider support.
Audit
Relevant operational metadata records the actor, action, resource, time and outcome where applicable.
Capability status
| Capability | Status | Meaning |
|---|---|---|
| BYOS with AWS S3Status: AvailableOrganization-selected AWS S3 environment | Status: Available | Organization-selected AWS S3 environment |
| Protected-file encryptionStatus: AvailableAES-256-GCM client-side before protected content reaches object storage | Status: Available | AES-256-GCM client-side before protected content reaches object storage |
| Organization rolesStatus: AvailableOwner / Admin / Member | Status: Available | Owner / Admin / Member |
| Rhea Key approvalStatus: AvailableHuman authentication/signing on the user's device | Status: Available | Human authentication/signing on the user's device |
| Cross-provider movementStatus: PlannedRequires additional provider integrations | Status: Planned | Requires additional provider integrations |
| BYODStatus: PlannedNot currently generally available | Status: Planned | Not currently generally available |
| Application/agent interfacesStatus: PlannedNo public integration surface claimed today | Status: Planned | No public integration surface claimed today |
Current RED operating model
Authority above. Storage below. RED in between.
Organizational authority
Owner · Admin · Member
Organizational permissions govern who may request sensitive actions.
Human authorization
Rhea Key · Supported Trezor hardware
Authentication, signing and approval on the user's device.
RED control infrastructure
Protect · Organize · Authorize · Access · Share · Move · Audit
The protection, authorization and audit model around your data.
Organization-selected storage
AWS S3
The organization's own AWS S3 environment.
This is the currently available RED operating model. Protected file content is encrypted client-side before reaching the organization's AWS S3 environment. RED maintains the verified protection, authorization and audit functions around those operations.
Data and trust boundary
What RED protects, and where the boundary sits.
Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.
If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.
Protected file content is encrypted with AES-256-GCM on the user's device before it reaches connected object storage.
Each protected document is encrypted with its own data-encryption key, which is wrapped for authorized recipients.
Deployment today
Organization-selected storage, starting with AWS S3.
Deployment status
| Storage / environment | Status | Meaning |
|---|---|---|
| AWS S3 (BYOS)Status: AvailableOrganization-selected AWS S3 environment | Status: Available | Organization-selected AWS S3 environment |
| Azure Blob StorageStatus: Planned | Status: Planned | — |
| Google Cloud StorageStatus: Planned | Status: Planned | — |
| Cloudflare R2Status: Planned | Status: Planned | — |
| Oracle Cloud Object StorageStatus: Planned | Status: Planned | — |
| S3-compatible storageStatus: PlannedBeyond the currently supported AWS S3 path | Status: Planned | Beyond the currently supported AWS S3 path |
| BYOD (Bring Your Own Database)Status: PlannedSupported database environments in the future | Status: Planned | Supported database environments in the future |
RED separates its protection and authorization model from the storage provider. AWS S3 is supported today; broader provider portability depends on planned integrations.
RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.
Not available today
- Public RED API or SDK documentation
- Generally available application integration
- Generally available agent integration
- BYOD and database integrations
- Multi-cloud object-storage support beyond AWS S3
- Rhea ID
- Rhea Key iOS
These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.
Where Rhea is going · Planned
Extending organizational control to every authorized actor.
Rhea's direction is to extend RED from human-controlled protected-file operations to supported databases, applications and controlled agent workflows. Planned interfaces are intended to let authorized systems request narrowly scoped operations under organizational policy, required human approval and audit.
Databases
Extend RED's protection, authorization and audit model to supported database environments.
Bring Your Own Database and every named database integration are planned and not currently generally available.
Applications
Allow authorized applications to request narrowly scoped operations through defined interfaces.
No public application-integration interface, API or SDK is available today.
Agents
Allow controlled agent workflows to request approved access without receiving unrestricted visibility into organizational data.
No agent integration surface is available today.
These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.
See architecture and direction