Product status
Everything, with its real status.
AWS S3 is Rhea Data's current public storage path. The tables below distinguish available capabilities, controlled pilots, work in development and planned expansion. Provider availability and the execution trust model are separate questions.
How to read this page
Four states, and only four.
Every status on this website resolves to one of these four. There is no fifth label, and no page defines its own wording.
Availability follows these tables and each feature's stated scope. Architectural diagrams illustrate direction; a provider name, product image or unlabeled sentence is not an availability guarantee.
Products and clients
What exists as a product you can use.
Rhea Data
- Status
- Status: Available
- What it is
- The governance, execution and evidence layer for organisational data.
Rhea Key Web
- Status
- Status: Available
- What it is
- Cryptographic authentication, signing, quorum approval and delegation.
Rhea Key Android
- Status
- Status: Coming soon
- What it is
- The native Android application is being prepared for release. The web interface works on Android today.
Rhea Key iOS
- Status
- Status: Coming soon
- What it is
- The native iOS application is being prepared for release. The web interface works on iOS today.
Rhea ID
- Status
- Status: Available
- What it is
- Signed Yes / No / Unknown answers to identity questions, without transferring documents.
Rhea ID native applications
- Status
- Status: Coming soon
- What it is
- The native enrolment applications are being prepared for release. Web enrolment and the relying-party API work today.
| Product | Status | What it is |
|---|---|---|
| Rhea Data | Status: Available | The governance, execution and evidence layer for organisational data. |
| Rhea Key Web | Status: Available | Cryptographic authentication, signing, quorum approval and delegation. |
| Rhea Key Android | Status: Coming soon | The native Android application is being prepared for release. The web interface works on Android today. |
| Rhea Key iOS | Status: Coming soon | The native iOS application is being prepared for release. The web interface works on iOS today. |
| Rhea ID | Status: Available | Signed Yes / No / Unknown answers to identity questions, without transferring documents. |
| Rhea ID native applications | Status: Coming soon | The native enrolment applications are being prepared for release. Web enrolment and the relying-party API work today. |
Capabilities
What Rhea Data does, and where each capability stands.
Protected documents
- Status
- Status: Available
- What it does
- Organize sensitive files in a document vault with folders, search, filters and per-item actions.
Client-side protection
- Status
- Status: Available
- What it does
- File contents are encrypted on the device with AES-256-GCM before connected storage receives them.
Secure Notes
- Status
- Status: Available
- What it does
- Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows.
Secure File Requests
- Status
- Status: Available
- What it does
- Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links.
Shared Access Control
- Status
- Status: Available
- What it does
- Share protected folders and files with defined members and keep the organization's access model intact.
Access and approvals
- Status
- Status: Available
- What it does
- Apply roles and permissions, and require Rhea Key approval for sensitive actions.
Encryption health
- Status
- Status: Available
- What it does
- Review protection coverage, key versions, and re-wrapping state across the organization's documents.
Sessions and security alerts
- Status
- Status: Available
- What it does
- Review active sessions and security alerts, and end sessions when required.
Guardian key recovery
- Status
- Status: Available
- What it does
- Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent.
Retention and archive
- Status
- Status: Available
- What it does
- Configure retention, archive documents, and control trash behavior.
Audit and evidence
- Status
- Status: Available
- What it does
- Review access, approval, administrative and security events, and verify the hash chain over cryptographic events.
Organization administration
- Status
- Status: Available
- What it does
- Manage members and roles, review usage and system health, and configure the organization.
AWS S3 connection (Bring Your Own Storage)
- Status
- Status: Available
- What it does
- Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from Rhea Data.
Classification
- Status
- Status: Available
- What it does
- Classify documents so that policy and review operate on sensitivity, not only on location.
Incident response workflows
- Status
- Status: Available
- What it does
- Coordinate response steps and record decisions against affected protected data.
Movement between connected S3 locations
- Status
- Status: Available
- What it does
- Move protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by Rhea Data.
Cross-provider movement
- Status
- Status: Available
- What it does
- Move protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation.
Customer-controlled connector execution
- Status
- Status: Available
- What it does
- In a Zero Custody deployment, a connector inside the customer's own VPC holds every provider credential and decryption key. It verifies scoped authority locally, enforces replay protection locally, and emits signed execution evidence.
Database connections (BYOD)
- Status
- Status: Available
- What it does
- Govern relational estates in place under scoped authority, starting with PostgreSQL. The database stays where it is; no migration is required.
Rhea Data API and SDK
- Status
- Status: Available
- What it does
- Interfaces for approved applications to request supported data operations under bounded, expiring authority.
Controlled agent authority
- Status
- Status: Available
- What it does
- Separate, scoped authority for AI agents and workloads, granted for one operation and one window, never by reusing a person's unrestricted session.
Encrypted filename and folder metadata
- Status
- Status: Available
- What it does
- Protect filenames and folder structure in addition to contents.
| Capability | Status | What it does |
|---|---|---|
| Protected documents | Status: Available | Organize sensitive files in a document vault with folders, search, filters and per-item actions. |
| Client-side protection | Status: Available | File contents are encrypted on the device with AES-256-GCM before connected storage receives them. |
| Secure Notes | Status: Available | Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows. |
| Secure File Requests | Status: Available | Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links. |
| Shared Access Control | Status: Available | Share protected folders and files with defined members and keep the organization's access model intact. |
| Access and approvals | Status: Available | Apply roles and permissions, and require Rhea Key approval for sensitive actions. |
| Encryption health | Status: Available | Review protection coverage, key versions, and re-wrapping state across the organization's documents. |
| Sessions and security alerts | Status: Available | Review active sessions and security alerts, and end sessions when required. |
| Guardian key recovery | Status: Available | Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent. |
| Retention and archive | Status: Available | Configure retention, archive documents, and control trash behavior. |
| Audit and evidence | Status: Available | Review access, approval, administrative and security events, and verify the hash chain over cryptographic events. |
| Organization administration | Status: Available | Manage members and roles, review usage and system health, and configure the organization. |
| AWS S3 connection (Bring Your Own Storage) | Status: Available | Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from Rhea Data. |
| Classification | Status: Available | Classify documents so that policy and review operate on sensitivity, not only on location. |
| Incident response workflows | Status: Available | Coordinate response steps and record decisions against affected protected data. |
| Movement between connected S3 locations | Status: Available | Move protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by Rhea Data. |
| Cross-provider movement | Status: Available | Move protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation. |
| Customer-controlled connector execution | Status: Available | In a Zero Custody deployment, a connector inside the customer's own VPC holds every provider credential and decryption key. It verifies scoped authority locally, enforces replay protection locally, and emits signed execution evidence. |
| Database connections (BYOD) | Status: Available | Govern relational estates in place under scoped authority, starting with PostgreSQL. The database stays where it is; no migration is required. |
| Rhea Data API and SDK | Status: Available | Interfaces for approved applications to request supported data operations under bounded, expiring authority. |
| Controlled agent authority | Status: Available | Separate, scoped authority for AI agents and workloads, granted for one operation and one window, never by reusing a person's unrestricted session. |
| Encrypted filename and folder metadata | Status: Available | Protect filenames and folder structure in addition to contents. |
Environments
Storage environments.
AWS S3 is the generally available storage path today. Every other environment carries its own status.
AWS S3
- Status
- Status: Available
- Note
- Customer-owned buckets
MinIO / S3-compatible
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Microsoft Azure Blob Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Google Cloud Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Oracle Cloud Object Storage
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Cloudflare R2
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Private and on-premises infrastructure
- Status
- Status: Available
- Note
- Customer-owned, connected in place
Databases (PostgreSQL and supported relational estates)
- Status
- Status: Available
- Note
- Governed in place, no migration
| Environment | Status | Note |
|---|---|---|
| AWS S3 | Status: Available | Customer-owned buckets |
| MinIO / S3-compatible | Status: Available | Customer-owned, connected in place |
| Microsoft Azure Blob Storage | Status: Available | Customer-owned, connected in place |
| Google Cloud Storage | Status: Available | Customer-owned, connected in place |
| Oracle Cloud Object Storage | Status: Available | Customer-owned, connected in place |
| Cloudflare R2 | Status: Available | Customer-owned, connected in place |
| Private and on-premises infrastructure | Status: Available | Customer-owned, connected in place |
| Databases (PostgreSQL and supported relational estates) | Status: Available | Governed in place, no migration |
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
Rhea Data uses a Bring Your Own Storage model. Your organisation connects storage and databases it already owns. Rhea does not provide, host, or operate customer storage, and no migration is required to begin.
Movement
Movement is two capabilities, not one.
Moving protected data between connected AWS S3 locations is a different operation from moving it across different providers, and the two do not share a status.
Movement between connected locations of one provider
- Status
- Status: Available
- Note
- A move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation.
Movement across different providers
- Status
- Status: Available
- Note
- A provider change is a governed operation, not a migration project.
| Operation | Status | Note |
|---|---|---|
| Movement between connected locations of one provider | Status: Available | A move copies the protected data to the destination and verifies it there. Deletion of the source object is a separate, explicitly authorised operation. |
| Movement across different providers | Status: Available | A provider change is a governed operation, not a migration project. |
Classification evidence
What each status covers.
Availability is specific to a feature, deployment and execution mode. Existing provider code does not by itself establish a supported release or independent customer-controlled enforcement.
MinIO and S3-compatible storage
Available
The S3-compatible execution path is the same path used for AWS S3: endpoint, region and credentials are supplied by the customer connection record, and every object written through it is client-encrypted before transfer. Self-hosted and sovereign object stores are therefore first-class targets rather than exceptions.
Microsoft Azure Blob Storage
Available
Azure Blob Storage is addressed through the same connection, placement, encryption and evidence pipeline as every other object store. Container, region and credential material belong to the customer subscription and are never required to leave it in a Zero Custody deployment.
Google Cloud Storage
Available
Google Cloud Storage buckets are connected with customer-supplied credentials and validated end to end — write, read, verify, audit — before the connection becomes usable, so a misconfigured bucket fails at connection time rather than during an operation.
Movement between connected locations of one provider
Available
Movement executes as a governed operation with checking, transfer, destination verification and an evidence record. The move copies to the destination and verifies it there; deleting the source is a separate authorised operation so that a failed verification can never destroy the only copy.
Movement across different providers
Available
Because protection is applied before an object reaches any provider, a cross-provider move is a transfer of already-protected objects plus a re-placement of their catalog and evidence records. Changing provider does not change the protection model, the keys or the audit history.
BYOD (Bring Your Own Database)
Available
Relational estates are governed in place: the connector executes authorised operations against the customer database under scoped authority, and every operation produces the same evidence record as a document operation. The database is not copied into Rhea and does not need to be migrated.
Multiple customer-owned storage locations in one organisation
Available
Cloud connections are held per organisation as a list with one default; each document is routed to a connection through folder and tag placement policy before encryption, and an explicit connection selector is shown at upload whenever more than one connection exists.
Rhea Key native mobile applications
Coming soon
The native Android and iOS applications for Rhea Key, and the Rhea ID mobile enrolment applications, are being prepared for release. Both products are fully usable today through their web cryptographic interfaces and their APIs, on every platform; the native applications add device-level convenience, not capability.
Evidence reviewed against the read-only product snapshots Rhea Data c62cb0f5 and Rhea Key Web 06dd55e on 17 August 2026.
Not available today
What a reader could otherwise assume already exists.
Only the native mobile applications are still to come. The web cryptographic interfaces and the relying-party APIs behind them work today, on every platform.
- Rhea Key native Android application (coming soon)
- Rhea Key native iOS application (coming soon)
- Rhea ID native mobile applications (coming soon)