Rhea

Audit

Evidence that a security review can actually use.

RED records what happened around protected data: who was authorized, what was approved, what was accessed, and what changed administratively.

Coverage

What is recorded.

  • Access to protected documents and notes.
  • Authorization decisions and Rhea Key approvals.
  • Sharing: member additions, removals and role changes.
  • Administrative and configuration changes.
  • Cryptographic and key-management events, covered by a hash chain that can be verified.

LimitationThe hash chain covers cryptographic and key-management events. RED does not claim that every record of every type is immutable.

How to use it

Questions the record answers.

  • Who opened this document, and under whose authorization?
  • When was this person's access removed, and what did they read before that?
  • Which sensitive actions required approval, and who approved them?
  • Has the cryptographic event chain been altered?

See it against your own environment.

Connect your own storage, protect a document, and read the recorded evidence yourself.