Recovery
Continuity without giving Rhea a copy of your authority.
Recovery is guardian-based, not escrow. Rhea's backend, together with its entire database, cannot reconstruct a recovered key.
How it works
A threshold of people, not a vendor.
- 01
Guardians are configured
The organization names guardians and a minimum threshold that must act together.
- 02
Each guardian holds their own material
A guardian holds a Recovery Kit protected by a passphrase only they know.
- 03
Recovery is requested
A recovery attempt is raised and the named guardians are asked to consent.
- 04
Each consent is signed and single-use
A consent authorizes one recovery, not a standing capability.
- 05
Reconstruction happens in the browser
Key material is reassembled on the device performing the recovery, never server-side.
The trade
The honest cost of not holding your keys.
A vendor that can restore your access on request can also be compelled to grant it to someone else. Rhea chose the other side of that trade, and the cost is real: recovery depends on your guardians being reachable and prepared.
LimitationIf a guardian loses both their Recovery Kit and its passphrase, that guardian's share is permanently lost. If enough shares are lost to fall below the threshold, the protected material cannot be recovered by anyone, including Rhea.
See it against your own environment.
Connect your own storage, protect a document, and read the recorded evidence yourself.