Who it is for
Important data. Clear permissions. Practical control.
RED is for organizations that need to protect, organize, collect and share important information on storage they control, with defined access and a record of activity.
Decision moments
When RED becomes relevant.
These are practical situations where a shared environment for data, permissions and recorded activity can help.
- Infrastructure administration must not equal permission to read.
- A person's future access must end when their role or relationship changes.
- Important files are still collected through email or loose links.
- The organization needs evidence of who accessed or approved what.
- Storage locations need to change without rebuilding the authority model.
- Protected files must be stored in customer-owned infrastructure.
Security and data-protection leaders
Infrastructure privileges should not decide who can read.
The problem today: Infrastructure privileges can result in readable-data access. Revocation and evidence are fragmented across systems. External sharing creates uncontrolled copies or links.
Outcome: Infrastructure administration and readable-data authority become separate responsibilities.
- Client-side protection before connected storage receives the content.
- Scoped authorization for named members.
- Recorded approvals and access.
- Controlled sharing and controlled collection.
Platform, cloud and data-infrastructure teams
One protection model instead of one per storage account.
The problem today: Controls are rebuilt around every storage account. Movement and provider changes fragment operational evidence. Security behavior becomes tied to provider-specific boundaries.
- Customer-owned AWS S3.
- Multiple connected AWS S3 locations in one organization.
- Governed movement between connected AWS S3 locations.
- One protection, authorization and evidence model above them.
LimitationCross-provider movement and database connectivity are Planned. MinIO and S3-compatible storage, Microsoft Azure Blob Storage and Google Cloud Storage are in controlled pilot.
Legal, finance, research and operational teams
Collect, share and manage important information.
The problem today: Important files arrive through email, attachments and temporary links. Access often survives beyond the relationship that justified it. It is difficult to answer who accessed what.
- Protected documents in an organizational workspace.
- Secure File Requests for controlled inbound collection.
- Shared Access Control for named participants.
- Secure Notes for credentials and procedures held by people.
- Retention, archive and recorded evidence.
Regulated and continuity-sensitive organizations
Information that must survive people, devices and infrastructure.
The problem today: Important information must survive staff, device and infrastructure changes. Access decisions need evidence. Compliance programmes require defensible technical controls.
- Recorded security and administrative activity.
- Guardian-based organizational recovery where configured.
- Customer-owned storage the organization can inspect directly.
LimitationRED provides technical controls that support a compliance programme. RED does not itself make an organization compliant, and Rhea does not claim certification under any specific regulatory framework.
Deployment roles
Who sponsors, operates and uses RED.
- Executive sponsor — CISO, CIO, CTO, data-protection leader or senior operational owner: Owns the decision that readable-data authority should sit with the organization rather than with infrastructure administration.
- Technical owner — Security, platform, cloud or data-infrastructure team: Connects customer-owned storage, configures organizational policy, roles and approvals, and reviews recorded activity.
- Daily users — Legal, finance, investment, research, engineering and operations teams: Protect, organize, share, request and retrieve important organizational files inside RED.
- External participants — Clients, partners, experts and contractors: Submit or receive controlled information through Secure File Requests and shared access, without a loose link or an unmanaged copy.
LimitationThese are representative deployment roles, not mandatory titles or a claim that every organization buys RED in the same way.
Fit
You are a strong fit today when several of these are true.
Current prerequisite: customer-owned AWS S3 for the available public storage path.
- It owns or controls the storage holding important organizational files.
- Infrastructure or cloud administrators should not automatically be able to read protected content.
- Employees, teams, clients, partners or contractors exchange important files.
- Access must be scoped, revoked and recorded.
- Files currently move through email, loose links, ordinary data rooms, shared drives or personal tools.
- The organization needs evidence of access, approval, sharing, administration or movement.
- Storage accounts or locations may change while protection and authorization must remain consistent.
- Business continuity cannot depend on one person, device or infrastructure administrator.
- The organization prefers customer-owned storage instead of vendor-hosted storage.
Current fit
What to check before choosing RED.
- You need a machine-secrets manager that injects credentials into application runtimes.
- You need protected structured data in a database today — database connectivity is Planned.
- You need a completed third-party certification or audit report as a procurement gate today.
- You cannot operate your own storage account and want the vendor to hold the data.
Industry context
Where this pattern shows up.
Industry is context, not the structure of the decision. The same authority problem appears across sectors.
- Legal and professional services — Case files, diligence rooms and client records shared with counsel, experts and clients, then closed cleanly.
- Finance and investment — Diligence material with scoped access, recorded approvals and a defined end of life.
- Healthcare and research — Sensitive records under narrow, revocable authority with recorded access for internal review.
- Engineering and regulated operations — Designs, credentials and procedures that must survive staff turnover and infrastructure change.
Start inside RED.
Explore RED, connect supported customer-owned storage and work through a document workflow. Review access and recorded activity in the same environment.