Security & trust
Security is a design constraint, not a marketing badge.
This page describes the current, verified security posture of RED and the surrounding Rhea infrastructure. It does not claim certifications, audits or guarantees that have not been performed.
Data protection
Protected file content is encrypted with AES-256-GCM on the user's device before it reaches connected object storage.
Each protected document is encrypted with its own data-encryption key, which is wrapped for authorized recipients.
Private authentication material remains protected by the user's device and is not transmitted to Rhea. Rhea does not operate a key-recovery service.
Data & trust boundary
Only encrypted protected-file content reaches connected object storage. RED and Rhea may still process the operational metadata required to provide authorization, organization administration, metering, security and audit functions.
If protected objects are copied from connected storage without the required decryption authority, the copied encrypted file content is not independently readable. This does not protect plaintext after authorized decryption or eliminate risks on a compromised authorized endpoint.
Audit & accountability
RED records relevant operational metadata for verified categories — actor, action, resource, time and outcome where applicable. Audit records contain operational metadata, not readable protected content.
Available audit behavior and contract-specific retention or export requirements can be reviewed during an enterprise security assessment.
Rhea does not sell customer data, build advertising profiles, or scan protected content for advertising.
Certifications & regulatory
Rhea does not currently publish third-party certifications or completed external audits. Enterprise security reviews are available on request.
Organizations operating under GDPR, NIS2, DORA, EHDS or sector-specific requirements may evaluate RED as one technical and organizational control within a broader compliance programme.
RED does not by itself make an organization compliant, and legal obligations depend on the organization's deployment, policies, processes, contracts and applicable law.
Organizational continuity
Rhea Key and Trezor-based authentication are non-custodial: private authentication material is guarded by the user's device and Rhea cannot reset or recover it on the user's behalf. Access removal is handled through authorized Owner and Admin workflows inside RED.
Organizations are responsible for maintaining multiple authorized Owners and Admins, planning for device replacement, and defining internal continuity controls for organizational access.
Responsible disclosure
We welcome coordinated security research and responsible disclosure of potential vulnerabilities. Please contact security@rhea.red with a clear description, reproduction steps and any supporting evidence. Do not access, modify or exfiltrate data that is not yours. Do not run destructive tests, and give us reasonable time to investigate before public disclosure.
A public bounty programme is not currently offered and no specific response time is guaranteed on this page.
A machine-readable record is available at /.well-known/security.txt.
Enterprise security review
For enterprise security reviews, architectural questions, deployment discussions or contract-level security requirements, contact enterprise@rhea.red. Relevant subprocessor information is available to enterprise customers and prospective customers on request.