RED
One environment for your organization's data.
RED (RheaData) brings protected documents, permissions and data workflows into one environment. Connect supported storage, organize information, control sharing and collection, move protected documents and review recorded activity. File content is encrypted on the device before it reaches storage.
Maturity
What RED is today
RED is generally available. AWS S3 is the generally available storage path; MinIO, Azure Blob Storage and Google Cloud Storage are in controlled pilot; every other environment carries its own status.
Use RED to organize protected documents and Secure Notes, request files from outside parties, share with defined members, approve sensitive actions and review what happened. The Command Center brings operational usage and organizational visibility together.
Ownership
Who deploys and uses RED.
RED is for organizations that need important information to remain protected and usable across teams, with controlled access, customer-owned storage and recorded activity. Security and infrastructure teams configure the environment; business teams use it for everyday data work.
- Sponsored by: Security, technology, data-protection or operational leadership.
- Operated by: Security, platform, cloud or data-infrastructure teams.
- Used by: Teams handling important organizational files.
- Extended to: Clients, partners and contractors through controlled sharing and collection.
LimitationRED serves human-controlled organizational file workflows today. Application authority, AI-agent authority, database connectivity and public integration interfaces are Planned.
Data operations
Put protected information to work.
Documents and Secure Notes, organized for the people authorized to use them.
Protected documents
Organize sensitive files in a document vault with folders, search, filters and per-item actions.
The organization keeps one place for the files it cannot afford to lose control of.
Evidence Access, sharing and lifecycle events are recorded.
Read moreClient-side protection
File contents are encrypted on the device with AES-256-GCM before connected storage receives them.
Storage receives protected objects, not readable content.
RED does not protect plaintext after an authorized decryption, and cannot eliminate risk on a compromised authorized endpoint.
Read moreSecure Notes
Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows.
Secrets stop living in chat messages, spreadsheets and personal note apps.
Evidence Creation, access and sharing of a note are recorded.
Secure Notes serve human-managed secrets. They are not a machine-secrets manager for application runtime injection.
Read moreEncrypted filename and folder metadata
Protect names and structure in addition to contents.
Removes the most significant remaining metadata exposure.
Exchange
Getting data in and out under control.
Collection and sharing stay inside the organization's protection model.
Secure File Requests
Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links.
Inbound sensitive material enters the organization's protection model at the point of collection.
Evidence Request creation, submission and receipt are recorded.
Read moreShared Access Control
Share protected folders and files with defined members and keep the organization's access model intact.
Sharing does not mean handing out a link that outlives the relationship.
Evidence Member additions, removals and file access are recorded.
Read moreSecurity operations
Running protection as an operation, not an assumption.
Access and approvals
Apply roles and permissions, and require Rhea Key approval for sensitive actions.
Authority to read is a decision the organization makes, not a side effect of infrastructure access.
Evidence Authorization decisions and approvals are recorded.
Read moreEncryption health
Review protection coverage, key versions, and re-wrapping state across the organization's documents.
Protection state becomes an operational metric instead of an assumption.
Read moreSessions and security alerts
Review active sessions and security alerts, and end sessions when required.
Access that is no longer appropriate can be ended immediately.
Read moreGuardian key recovery
Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent.
Continuity does not require Rhea to hold a copy of the organization's authority.
If a guardian loses both their Recovery Kit and its passphrase, that guardian's share is permanently lost.
Read moreRetention and archive
Configure retention, archive documents, and control trash behavior.
Sensitive material has a defined end of life.
Read moreClassification
Classify documents so that policy and review can operate on sensitivity, not only on location.
Controls follow the sensitivity of the information.
Infrastructure
Your storage. Your account. Your control.
RED connects to storage the organization already owns and operates.
AWS S3 connection (Bring Your Own Storage)
Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from RED.
The organization keeps ownership of the storage account holding its protected objects.
Read moreMovement between connected S3 locations
Move protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by RED.
Storage layout can change without the organization abandoning its protection and evidence model.
A move copies the protected data to the destination. The source object is not deleted by the move itself.
Read moreCross-provider movement
Move protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation.
Changing provider becomes an operation rather than a migration project.
Read moreDatabase connections (BYOD)
Planned customer-side database operations under scoped authority, starting with PostgreSQL.
Structured data faces the same control problem as documents.
RED API and SDK
Planned interfaces for approved applications to request supported data operations under bounded authority.
Applications become authorized actors instead of exceptions.
Category
How RED fits into your stack.
RED combines data workflows, protection, permissions and recorded activity. These responsibilities explain its role:
- Your connected provider continues to hold the stored data.
- RED provides the environment for supported data operations.
- Encryption protects file content before storage.
- Rhea Key supports authentication and approvals.
- Your existing identity and security controls still matter.
- Customer-controlled execution is the next architectural step.
Administration
Members, roles and evidence.
Organization administration
Manage members and roles, review usage and system health, and configure the organization.
One control surface for the people and settings around protected data.
Read moreAudit and evidence
Review access, approval, administrative and security events, and verify the hash chain over cryptographic events.
The organization can show what happened, not only assert it.
The hash chain covers cryptographic and key-management events. It is not a claim that every record of every type is immutable.
Read moreRED pricing
Priced on the data RED processes, not on the storage you own.
RED usage is based on the amount of data RED processes each month, including encryption, decryption and related processing. VAT may apply. Plans are activated inside RED after organization setup.
All plans include encryption on the device before storage and Bring Your Own Storage. RED offers a native 7-day trial.
- Operations are billed at €0.01 per 1,000 operations.
- Only relay-processed data is charged at 10× the selected plan's data rate. The relay portion is charged once, not at both the standard and relay rate.
- Customer-owned storage-provider charges are separate and paid directly by the customer.
Launch
€399
/ organization / month
€0.60
/ GiB processed
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Growth
€1,499
/ organization / month
€0.15
/ GiB processed
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Expand
€2,799
/ organization / month
€0.08
/ GiB processed
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Scale
€4,999
/ organization / month
€0.05
/ GiB processed
- Encryption on the device before storage
- Bring Your Own Storage
- Access, permission and approval activity recorded
Custom
For requirements outside the standard plans.
Estimate monthly usage
Pricing estimator
Enter the data RED processes each month and the number of operations. The cheapest standard plan is selected for you.
Everything RED encrypts, decrypts or otherwise processes for your organization.
Data that goes through the RED relay instead of the direct storage path. This portion is billed once, at 10× the plan rate.
Counted per request, metered at €0.01 per 1,000 operations.
Estimated monthly total
€1,601.50
on the Launch plan (cheapest at this usage)
- Base fee
- €399
- Direct data — 2,000 GiB
- €1,200
- Relay data — 0 GiB at 10×
- €0
- Operations — 250,000
- €2.50
- Estimated monthly total
- €1,601.50
Relay-processed data is charged once, at the relay rate only. This is an estimate, not an invoice or binding quote. It excludes VAT, external storage charges and contract-specific terms. Actual billing is determined inside RED.
Start inside RED.
Explore RED, connect supported customer-owned storage and work through a document workflow. Review permissions and recorded activity in the same environment.