Security & Trust
Security is a design constraint, not a marketing badge.
This page describes the security posture of RED and the surrounding Rhea infrastructure in specific, verifiable terms. It does not claim certifications or audits that have not been performed.
Data protection
RED applies AES-256-GCM encryption on the client before protected file content reaches connected object storage. The storage provider receives ciphertext.
Each protected document is encrypted using its own data-encryption key. That key is wrapped for authorized organizational access and is not stored by Rhea in a form that independently enables Rhea to decrypt the document.
Decryption authorization is governed by the document's key authority and RED's runtime key-release controls. Rhea does not maintain plaintext copies of protected file content or unwrapped document keys.
Audit & accountability
RED records operational metadata for relevant protected-data activity, including the actor, organization, action, affected resource, time and outcome where applicable. Audit records do not contain readable protected file contents.
Recorded categories include:
- Access attempts and outcomes
- Permission changes
- Approval activity
- Organization administration events
- Encryption and decryption operations
- Relevant protected-document lifecycle events
Retention and export characteristics are configured inside RED and are described in the application. This page does not make claims of immutability, legal non-repudiation, or certification against a specific standard.
Organizational continuity
Rhea Key and Trezor-based authentication are non-custodial: private authentication material is guarded by the user's device and Rhea cannot reset or recover it on the user's behalf. Access removal is handled through authorized Owner and Administrator workflows inside RED.
Organizations are responsible for maintaining multiple authorized administrators, planning for device replacement, and defining internal continuity controls for organizational access.
Responsible disclosure
We welcome coordinated security research and responsible disclosure of potential vulnerabilities. Please contact security@rhea.red with a clear description, reproduction steps and any supporting evidence. Do not access, modify or exfiltrate data that is not yours. Do not run destructive tests, and give us reasonable time to investigate before public disclosure.
A public bounty programme is not currently offered and no specific response time is guaranteed on this page.
A machine-readable record is available at /.well-known/security.txt.
Enterprise security review
For enterprise security reviews, architectural questions, deployment discussions or contract-level security requirements, contact enterprise@rhea.red. Relevant subprocessor information is available to enterprise customers and prospective customers on request.