Who it is for
Provable authority over institutional data.
Rhea Data is for organizations that need to protect, organize, collect and share important information on storage they control, with defined access and a record of activity.
Decision moments
When Rhea Data becomes relevant.
These are practical situations where a shared environment for data, permissions and recorded activity can help.
- Infrastructure administration must not equal permission to read.
- A person's future access must end when their role or relationship changes.
- Important files are still collected through email or loose links.
- The organization needs evidence of who accessed or approved what.
- Storage locations need to change without rebuilding the authority model.
- Protected files must be stored in customer-owned infrastructure.
Institutional motions
Four institutions. One requirement.
Central banks, governments, regulated health and legal organisations, and enterprises running AI agent estates arrive from different pressures and land on the same requirement: the authority to read must be held inside the institution, and the proof must survive without the vendor.
Central banks and systemic financial institutions
A settlement system cannot rest on vendor trust.
Supervisors no longer accept a contractual assurance as a control. They ask who could technically read the data, and the honest answer at most institutions includes several third parties.
Authority to read or export is bound to an M-of-N quorum of executive keys held inside the institution. Rhea coordinates the operation and cannot perform it, so the honest answer becomes: nobody outside this building.
- Quorum approval on exports, policy mutations and key rotations
- Immutable hash-chained audit trails, verifiable without Rhea
- Zero Custody execution inside the institution's own environment
- Provider change as a governed operation, not a migration programme
LimitationMeasured against: DORA · Basel III / BCBS 239 · ISO 27001
Governments and sovereign defence
Sovereignty is a key custody question, not a map question.
A national data estate hosted in-region on foreign infrastructure is in-region, not sovereign. The operator of that infrastructure remains technically capable of access, and remains subject to a foreign legal order.
Decryption authority never enters the provider's environment. A sovereign region, a national data centre or an air-gapped connector executes under keys the state holds, and the provider handles ciphertext.
- Air-gapped connector deployment
- No foreign-operator path to plaintext, by construction
- Classification-aware policy, evaluated fail-closed
- Offline-verifiable evidence for oversight bodies
LimitationMeasured against: National sovereignty frameworks · NIS2 · Defence classification regimes
Regulated health, life sciences and legal
Patient and client data that can be used, and still cannot leak.
Clinical trial data and privileged client material must move between organisations to be useful, and every movement multiplies the number of parties holding a readable copy.
The data moves protected and stays protected. A collaborator receives a bounded, expiring authority to perform one operation, and the record of that operation is evidence in itself.
- Bounded external collaboration without permanent copies
- Controlled inbound collection of sensitive material
- Per-operation evidence suitable for audit and litigation hold
- Guardian-based recovery with no vendor escrow
LimitationMeasured against: HIPAA · GDPR · GxP · Legal professional privilege
Enterprise AI agent estates
An agent with a permanent API token is a standing breach.
Autonomous agents are being given the credentials of the humans they assist. Those credentials are broad, permanent, and indistinguishable from a real operator once stolen.
An agent receives a delegation instead of a credential: one named operation, one time window, revocable instantly, and recorded. When the window closes, the authority is gone without rotating anything else.
- Bounded machine delegations issued from a holder key
- Per-operation authorisation, evaluated fail-closed
- Full attribution of agent actions in the evidence chain
- Instant revocation without estate-wide credential rotation
LimitationMeasured against: EU AI Act · NIST AI Risk Management Framework · ISO 42001
Security and data-protection leaders
Infrastructure privileges should not decide who can read.
The problem today: Infrastructure privileges can result in readable-data access. Revocation and evidence are fragmented across systems. External sharing creates uncontrolled copies or links.
Outcome: Infrastructure administration and readable-data authority become separate responsibilities.
- Client-side protection before connected storage receives the content.
- Scoped authorization for named members.
- Recorded approvals and access.
- Controlled sharing and controlled collection.
Platform, cloud and data-infrastructure teams
One protection model instead of one per storage account.
The problem today: Controls are rebuilt around every storage account. Movement and provider changes fragment operational evidence. Security behavior becomes tied to provider-specific boundaries.
- Customer-owned AWS S3.
- Multiple connected AWS S3 locations in one organization.
- Governed movement between connected AWS S3 locations.
- One protection, authorization and evidence model above them.
LimitationCross-provider movement and database connectivity are Planned. MinIO and S3-compatible storage, Microsoft Azure Blob Storage and Google Cloud Storage are in controlled pilot.
Legal, finance, research and operational teams
Collect, share and manage important information.
The problem today: Important files arrive through email, attachments and temporary links. Access often survives beyond the relationship that justified it. It is difficult to answer who accessed what.
- Protected documents in an organizational workspace.
- Secure File Requests for controlled inbound collection.
- Shared Access Control for named participants.
- Secure Notes for credentials and procedures held by people.
- Retention, archive and recorded evidence.
Regulated and continuity-sensitive organizations
Information that must survive people, devices and infrastructure.
The problem today: Important information must survive staff, device and infrastructure changes. Access decisions need evidence. Compliance programmes require defensible technical controls.
- Recorded security and administrative activity.
- Guardian-based organizational recovery where configured.
- Customer-owned storage the organization can inspect directly.
LimitationRhea Data provides technical controls that support a compliance programme. Rhea Data does not itself make an organization compliant, and Rhea does not claim certification under any specific regulatory framework.
Deployment roles
Who sponsors, operates and uses Rhea Data.
- Executive sponsor — CISO, CIO, CTO, data-protection leader or senior operational owner: Owns the decision that readable-data authority should sit with the organization rather than with infrastructure administration.
- Technical owner — Security, platform, cloud or data-infrastructure team: Connects customer-owned storage, configures organizational policy, roles and approvals, and reviews recorded activity.
- Daily users — Legal, finance, investment, research, engineering and operations teams: Protect, organize, share, request and retrieve important organizational files inside Rhea Data.
- External participants — Clients, partners, experts and contractors: Submit or receive controlled information through Secure File Requests and shared access, without a loose link or an unmanaged copy.
LimitationThese are representative deployment roles, not mandatory titles or a claim that every organization buys Rhea Data in the same way.
Fit
You are a strong fit today when several of these are true.
Current prerequisite: customer-owned AWS S3 for the available public storage path.
- It owns or controls the storage holding important organizational files.
- Infrastructure or cloud administrators should not automatically be able to read protected content.
- Employees, teams, clients, partners or contractors exchange important files.
- Access must be scoped, revoked and recorded.
- Files currently move through email, loose links, ordinary data rooms, shared drives or personal tools.
- The organization needs evidence of access, approval, sharing, administration or movement.
- Storage accounts or locations may change while protection and authorization must remain consistent.
- Business continuity cannot depend on one person, device or infrastructure administrator.
- The organization prefers customer-owned storage instead of vendor-hosted storage.
Current fit
What to check before choosing Rhea Data.
- You need a machine-secrets manager that injects credentials into application runtimes.
- You need protected structured data in a database today — database connectivity is Planned.
- You need a completed third-party certification or audit report as a procurement gate today.
- You cannot operate your own storage account and want the vendor to hold the data.
Industry context
Where this pattern shows up.
Industry is context, not the structure of the decision. The same authority problem appears across sectors.
- Legal and professional services — Case files, diligence rooms and client records shared with counsel, experts and clients, then closed cleanly.
- Finance and investment — Diligence material with scoped access, recorded approvals and a defined end of life.
- Healthcare and research — Sensitive records under narrow, revocable authority with recorded access for internal review.
- Engineering and regulated operations — Designs, credentials and procedures that must survive staff turnover and infrastructure change.
Start inside Rhea Data.
Explore Rhea Data, connect supported customer-owned storage and work through a document workflow. Review access and recorded activity in the same environment.