Rhea

Storage connections and movement

Bring your own storage. Keep your own account.

RED does not sell storage. It connects to the storage the organization already owns, writes protected objects into it, and keeps the authority to read those objects outside the provider.

Status: Available today

Connecting

From credentials to an operating connection.

  1. 01

    Provide your own storage credentials

    RED connects to an environment your organization owns and pays for.

  2. 02

    Validation and transfer test

    The connection is validated and the transfer path is tested before it carries protected data.

  3. 03

    Operate from RED

    Protected objects are written to and read from your environment through the connection.

Environments

Every environment carries its own status.

Every environment carries its own status.
EnvironmentStatusNote
AWS S3Status: Available todayApproved public storage path today
MinIO / S3-compatibleStatus: Coming soonImplemented; enabled per deployment
Microsoft Azure Blob StorageStatus: Coming soonImplemented; enabled per deployment
Google Cloud StorageStatus: Coming soonImplemented; enabled per deployment
Oracle Cloud Object StorageStatus: PlannedDirection
Cloudflare R2Status: PlannedDirection
Private and on-premises infrastructureStatus: PlannedDirection
DatabasesStatus: PlannedDirection

Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.

Movement

Infrastructure changes. The protection model should not.

The reason to keep authority outside the provider is that providers change. Contracts end, regions get consolidated, an acquisition brings a second cloud, a regulator asks for a different jurisdiction.

Cross-storage move is the planned operation for that: select protected data, choose another connected destination, and let RED handle checking, transfer, verification, cutover, cleanup and audit.

LimitationCross-storage move is planned. Today, moving data between storage locations copies it — the source object is not deleted by the move itself.

Credentials

What Rhea holds on your behalf.

To operate a connection, Rhea stores your storage provider credentials and can decrypt them server-side. That is a real trust boundary and the site states it plainly: Rhea can decrypt your storage credentials. Rhea cannot decrypt your file contents with them, because file keys are not held server-side.

LimitationStorage provider credentials are recoverable by Rhea's backend. Scope the credentials you provide to the bucket RED needs.

Provider independence

Your data stays where you choose.

RED protects data inside storage the organization already owns and operates. Nothing has to move into Rhea-owned infrastructure for RED to protect, authorize and record it.

File contents are encrypted on your device with AES-256-GCM before anything reaches storage. Connected storage receives ciphertext only.

Storage environments

  • AWS S3

    Approved public storage path today

  • MinIO / S3-compatible

    Implemented; enabled per deployment

    Status: Coming soon
  • Microsoft Azure Blob Storage

    Implemented; enabled per deployment

    Status: Coming soon
  • Google Cloud Storage

    Implemented; enabled per deployment

    Status: Coming soon
  • Oracle Cloud Object Storage

    Direction

    Status: Planned
  • Cloudflare R2

    Direction

    Status: Planned
  • Private and on-premises infrastructure

    Direction

    Status: Planned
  • Databases

    Direction

    Status: Planned

Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.

Available

Bring Your Own Storage

Connect your organization's AWS S3 environment. File contents are encrypted on the device before the provider receives them, and RED maintains the protection, authorization and audit model around them.

Planned

Status: Planned

Bring Your Own Database

Intended to extend the same protection, authorization and audit model to supported database environments. Not available today.

Direction

Status: Planned
PostgreSQLMySQLSQL ServerOracleMongoDBSupabaseFirebaseSnowflakeBigQueryDatabricks

Named environments indicate direction only. None is available today.

See it against your own environment.

Connect your own storage, protect a document, and read the recorded evidence yourself.