Storage connections and movement
Bring your own storage. Keep your own account.
RED does not sell storage. It connects to the storage the organization already owns, writes protected objects into it, and keeps the authority to read those objects outside the provider.
Connecting
From credentials to an operating connection.
- 01
Provide your own storage credentials
RED connects to an environment your organization owns and pays for.
- 02
Validation and transfer test
The connection is validated and the transfer path is tested before it carries protected data.
- 03
Operate from RED
Protected objects are written to and read from your environment through the connection.
Environments
Every environment carries its own status.
AWS S3
- Status
- Status: Available today
- Note
- Generally available storage path
MinIO / S3-compatible
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Microsoft Azure Blob Storage
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Google Cloud Storage
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Oracle Cloud Object Storage
- Status
- Status: Planned
- Note
- Direction
Cloudflare R2
- Status
- Status: Planned
- Note
- Direction
Private and on-premises infrastructure
- Status
- Status: Planned
- Note
- Direction
Databases
- Status
- Status: Planned
- Note
- Direction
| Environment | Status | Note |
|---|---|---|
| AWS S3 | Status: Available today | Generally available storage path |
| MinIO / S3-compatible | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Microsoft Azure Blob Storage | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Google Cloud Storage | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Oracle Cloud Object Storage | Status: Planned | Direction |
| Cloudflare R2 | Status: Planned | Direction |
| Private and on-premises infrastructure | Status: Planned | Direction |
| Databases | Status: Planned | Direction |
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Movement
Two different operations, two different statuses.
Movement between connected AWS S3 locations
- Status
- Status: Available today
- Note
- A move copies the protected data to the destination. The source object is not deleted by the move itself.
Movement across different providers
- Status
- Status: Planned
- Note
- Cross-provider movement is not available today
| Operation | Status | Note |
|---|---|---|
| Movement between connected AWS S3 locations | Status: Available today | A move copies the protected data to the destination. The source object is not deleted by the move itself. |
| Movement across different providers | Status: Planned | Cross-provider movement is not available today |
Movement
Infrastructure changes. The protection model should not.
The reason to keep authority outside the provider is that providers change. Contracts end, regions get consolidated, an acquisition brings a second cloud, a regulator asks for a different jurisdiction.
Today RED moves protected data between the AWS S3 locations you have connected: select the data, choose the destination, and RED handles checking, transfer, verification and audit. Protection and authority do not change during the move.
Movement across different providers — for example AWS S3 to Azure Blob Storage — is planned and not available today.
LimitationA move copies the protected data to the destination. The source object is not deleted by the move itself.
Credentials
What Rhea holds on your behalf.
To operate a connection, Rhea stores your storage provider credentials and can decrypt them server-side. That is a real trust boundary and the site states it plainly: Rhea can decrypt your storage credentials. Rhea cannot decrypt your file contents with them, because file keys are not held server-side.
LimitationStorage provider credentials are recoverable by Rhea's backend. Scope the credentials you provide to the bucket RED needs.
Provider independence
Your data stays where you choose.
RED protects data inside storage the organization already owns and operates. Nothing has to move into Rhea-owned infrastructure for RED to protect, authorize and record it.
File contents are encrypted on your device with AES-256-GCM before anything reaches storage. Connected storage receives ciphertext only.
Storage environments
AWS S3
Generally available storage path
MinIO / S3-compatible
Implemented; enabled for selected deployments
Status: Controlled pilotMicrosoft Azure Blob Storage
Implemented; enabled for selected deployments
Status: Controlled pilotGoogle Cloud Storage
Implemented; enabled for selected deployments
Status: Controlled pilotOracle Cloud Object Storage
Direction
Status: PlannedCloudflare R2
Direction
Status: PlannedPrivate and on-premises infrastructure
Direction
Status: PlannedDatabases
Direction
Status: Planned
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Available
Bring Your Own Storage
Connect your organization's AWS S3 environment. File contents are encrypted on the device before the provider receives them, and RED maintains the protection, authorization and audit model around them.
Planned
Status: PlannedBring Your Own Database
Intended to extend the same protection, authorization and audit model to supported database environments. Not available today.
Direction
Status: PlannedNamed environments indicate direction only. None is available today.
Start inside RED.
Explore RED, connect supported customer-owned storage and work through a document workflow. Review permissions and recorded activity in the same environment.