Storage connections and movement
Bring your own storage. Keep your own account.
Rhea Data does not sell storage. It connects to the storage the organization already owns, writes protected objects into it, and keeps the authority to read those objects outside the provider.
Connecting
From credentials to an operating connection.
- 01
Provide your own storage credentials
Rhea Data connects to an environment your organization owns and pays for.
- 02
Validation and transfer test
The connection is validated and the transfer path is tested before it carries protected data.
- 03
Operate from Rhea Data
Protected objects are written to and read from your environment through the connection.
Environments
Every environment carries its own status.
AWS S3
- Status
- Status: Available
- Note
- Customer-owned buckets
MinIO / S3-compatible
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Microsoft Azure Blob Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Google Cloud Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Oracle Cloud Object Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Cloudflare R2
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Private and on-premises infrastructure
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Databases (PostgreSQL and supported relational estates)
- Status
- Status: Available
- Note
- Governed in place, no migration
| Environment | Status | Note |
|---|---|---|
| AWS S3 | Status: Available | Customer-owned buckets |
| MinIO / S3-compatible | Status: Available | Customer-owned, connected in place |
| Microsoft Azure Blob Storage | Status: Available | Customer-owned, connected in place |
| Google Cloud Storage | Status: Available | Customer-owned, connected in place |
| Oracle Cloud Object Storage | Status: Available | Customer-owned, connected in place |
| Cloudflare R2 | Status: Available | Customer-owned, connected in place |
| Private and on-premises infrastructure | Status: Available | Customer-owned, connected in place |
| Databases (PostgreSQL and supported relational estates) | Status: Available | Governed in place, no migration |
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Movement
Two different operations, two different statuses.
Movement between connected locations of one provider
- Status
- Status: Available
- Note
- A move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation.
Movement across different providers
- Status
- Status: Available
- Note
- A provider change is a governed operation, not a migration project.
| Operation | Status | Note |
|---|---|---|
| Movement between connected locations of one provider | Status: Available | A move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation. |
| Movement across different providers | Status: Available | A provider change is a governed operation, not a migration project. |
Movement
Infrastructure changes. The protection model should not.
The reason to keep authority outside the provider is that providers change. Contracts end, regions get consolidated, an acquisition brings a second cloud, a regulator asks for a different jurisdiction.
Today Rhea Data moves protected data between the AWS S3 locations you have connected: select the data, choose the destination, and Rhea Data handles checking, transfer, verification and audit. Protection and authority do not change during the move.
Movement across different providers — for example AWS S3 to Azure Blob Storage — is planned and not available today.
LimitationA move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation.
Credential modes
Choose who is able to open your storage keys.
Hardened — client-encrypted direct storage
- Can Rhea open the credentials?
- No. Rhea holds no key that opens the envelope.
- Payload path
- Your browser signs each request and transfers directly to your own bucket.
- Setup required
- A CORS rule on your bucket allowing requests from the Rhea Data application.
Standard — Rhea-operated connection
- Can Rhea open the credentials?
- Yes — storage credentials only, never document keys or contents.
- Payload path
- Rhea's backend issues presigned URLs and performs server-side storage operations.
- Setup required
- A scoped storage user. No bucket CORS configuration needed.
| Mode | Can Rhea open the credentials? | Payload path | Setup required |
|---|---|---|---|
| Hardened — client-encrypted direct storage | No. Rhea holds no key that opens the envelope. | Your browser signs each request and transfers directly to your own bucket. | A CORS rule on your bucket allowing requests from the Rhea Data application. |
| Standard — Rhea-operated connection | Yes — storage credentials only, never document keys or contents. | Rhea's backend issues presigned URLs and performs server-side storage operations. | A scoped storage user. No bucket CORS configuration needed. |
Hardened mode is the recommended standard for regulated organisations. Standard mode stays available where server-side background operation matters more.
Credentials
What Rhea holds on your behalf.
In Hardened mode you still type your keys into the same form, but the page seals them under a key derived from your Rhea Key signature before anything is sent. Rhea stores an envelope it cannot open, and your browser signs each storage request itself and transfers directly to your bucket.
In Standard mode, Rhea stores those credentials and can decrypt them server-side to operate the connection on your behalf. That is a real trust boundary and the site states it plainly.
In both modes Rhea cannot decrypt your file contents, because file keys are not held server-side.
LimitationHardened mode requires a rule on your own bucket permitting requests from the Rhea Data application. In Standard mode, storage provider credentials are recoverable by Rhea's backend — scope the credentials you provide to the bucket Rhea Data needs.
Provider independence
Your data stays where you choose.
Rhea Data protects data inside storage the organization already owns and operates. Nothing has to move into Rhea-owned infrastructure for Rhea Data to protect, authorize and record it.
File contents are encrypted on your device with AES-256-GCM before anything reaches storage. Connected storage receives ciphertext only.
Storage environments
AWS S3
Customer-owned buckets
MinIO / S3-compatible
Customer-owned, connected in place
Microsoft Azure Blob Storage
Customer-owned, connected in place
Google Cloud Storage
Customer-owned, connected in place
Oracle Cloud Object Storage
Customer-owned, connected in place
Cloudflare R2
Customer-owned, connected in place
Private and on-premises infrastructure
Customer-owned, connected in place
Databases (PostgreSQL and supported relational estates)
Governed in place, no migration
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Available
Bring Your Own Storage
Connect your organization's AWS S3 environment. File contents are encrypted on the device before the provider receives them, and Rhea Data maintains the protection, authorization and audit model around them.
Planned
Status: In designBring Your Own Database
Intended to extend the same protection, authorization and audit model to supported database environments. Not available today.
Direction
Status: In designNamed environments indicate direction only. None is available today.
Start inside Rhea Data.
Explore Rhea Data, connect supported customer-owned storage and work through a document workflow. Review permissions and recorded activity in the same environment.