Product status
Everything, with its real status.
AWS S3 is RED's current public storage path. The tables below distinguish available capabilities, controlled pilots, work in development and planned expansion. Provider availability and the execution trust model are separate questions.
How to read this page
Four states, and only four.
Every status on this website resolves to one of these four. There is no fifth label, and no page defines its own wording.
Availability follows these tables and each feature's stated scope. Architectural diagrams illustrate direction; a provider name, product image or unlabeled sentence is not an availability guarantee.
Products and clients
What exists as a product you can use.
RED
- Status
- Status: Available today
- What it is
- Operating environment for protected data, permissions and everyday data workflows.
Rhea Key Web
- Status
- Status: Available today
- What it is
- Cryptographic authentication, signing and approval
Rhea Key Android
- Status
- Status: Available today
- What it is
- Cryptographic authentication, signing and approval
Rhea Key iOS
- Status
- Status: Coming soon
- What it is
- iOS client in development
Rhea ID
- Status
- Status: Coming soon
- What it is
- Verified identity or selected attributes
| Product | Status | What it is |
|---|---|---|
| RED | Status: Available today | Operating environment for protected data, permissions and everyday data workflows. |
| Rhea Key Web | Status: Available today | Cryptographic authentication, signing and approval |
| Rhea Key Android | Status: Available today | Cryptographic authentication, signing and approval |
| Rhea Key iOS | Status: Coming soon | iOS client in development |
| Rhea ID | Status: Coming soon | Verified identity or selected attributes |
Capabilities
What RED does, and where each capability stands.
Protected documents
- Status
- Status: Available today
- What it does
- Organize sensitive files in a document vault with folders, search, filters and per-item actions.
Client-side protection
- Status
- Status: Available today
- What it does
- File contents are encrypted on the device with AES-256-GCM before connected storage receives them.
Secure Notes
- Status
- Status: Available today
- What it does
- Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows.
Secure File Requests
- Status
- Status: Available today
- What it does
- Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links.
Shared Access Control
- Status
- Status: Available today
- What it does
- Share protected folders and files with defined members and keep the organization's access model intact.
Access and approvals
- Status
- Status: Available today
- What it does
- Apply roles and permissions, and require Rhea Key approval for sensitive actions.
Encryption health
- Status
- Status: Available today
- What it does
- Review protection coverage, key versions, and re-wrapping state across the organization's documents.
Sessions and security alerts
- Status
- Status: Available today
- What it does
- Review active sessions and security alerts, and end sessions when required.
Guardian key recovery
- Status
- Status: Available today
- What it does
- Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent.
Retention and archive
- Status
- Status: Available today
- What it does
- Configure retention, archive documents, and control trash behavior.
Audit and evidence
- Status
- Status: Available today
- What it does
- Review access, approval, administrative and security events, and verify the hash chain over cryptographic events.
Organization administration
- Status
- Status: Available today
- What it does
- Manage members and roles, review usage and system health, and configure the organization.
AWS S3 connection (Bring Your Own Storage)
- Status
- Status: Available today
- What it does
- Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from RED.
Classification
- Status
- Status: Coming soon
- What it does
- Classify documents so that policy and review can operate on sensitivity, not only on location.
Incident response workflows
- Status
- Status: Coming soon
- What it does
- Coordinate response steps and record decisions against affected protected data.
Movement between connected S3 locations
- Status
- Status: Available today
- What it does
- Move protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by RED.
Cross-provider movement
- Status
- Status: Planned
- What it does
- Move protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation.
Customer-controlled connector execution
- Status
- Status: Coming soon
- What it does
- Independent verification of scoped customer authority in the customer's environment, with local replay protection and signed execution evidence. In development; distinct from today's provider connection paths.
Database connections (BYOD)
- Status
- Status: Planned
- What it does
- Planned customer-side database operations under scoped authority, starting with PostgreSQL.
RED API and SDK
- Status
- Status: Planned
- What it does
- Planned interfaces for approved applications to request supported data operations under bounded authority.
Controlled agent authority
- Status
- Status: Planned
- What it does
- Planned separate, scoped authority for AI agents and workloads, without reusing a person's unrestricted session.
Encrypted filename and folder metadata
- Status
- Status: Planned
- What it does
- Protect names and structure in addition to contents.
| Capability | Status | What it does |
|---|---|---|
| Protected documents | Status: Available today | Organize sensitive files in a document vault with folders, search, filters and per-item actions. |
| Client-side protection | Status: Available today | File contents are encrypted on the device with AES-256-GCM before connected storage receives them. |
| Secure Notes | Status: Available today | Keep passwords, recovery information, private keys, procedures and sensitive text inside controlled human workflows. |
| Secure File Requests | Status: Available today | Request and receive sensitive files from people inside or outside the organization without defaulting to ordinary attachments or uncontrolled upload links. |
| Shared Access Control | Status: Available today | Share protected folders and files with defined members and keep the organization's access model intact. |
| Access and approvals | Status: Available today | Apply roles and permissions, and require Rhea Key approval for sensitive actions. |
| Encryption health | Status: Available today | Review protection coverage, key versions, and re-wrapping state across the organization's documents. |
| Sessions and security alerts | Status: Available today | Review active sessions and security alerts, and end sessions when required. |
| Guardian key recovery | Status: Available today | Recover organizational key material through a configured threshold of guardians who each hold their own key and give a signed, single-use consent. |
| Retention and archive | Status: Available today | Configure retention, archive documents, and control trash behavior. |
| Audit and evidence | Status: Available today | Review access, approval, administrative and security events, and verify the hash chain over cryptographic events. |
| Organization administration | Status: Available today | Manage members and roles, review usage and system health, and configure the organization. |
| AWS S3 connection (Bring Your Own Storage) | Status: Available today | Connect the organization's own AWS S3 environment, validate it, test the transfer path, and operate it from RED. |
| Classification | Status: Coming soon | Classify documents so that policy and review can operate on sensitivity, not only on location. |
| Incident response workflows | Status: Coming soon | Coordinate response steps and record decisions against affected protected data. |
| Movement between connected S3 locations | Status: Available today | Move protected data between the organization's connected AWS S3 locations, with checking, transfer, verification and audit handled by RED. |
| Cross-provider movement | Status: Planned | Move protected data between different providers — for example AWS S3 to Azure Blob Storage — as one governed operation. |
| Customer-controlled connector execution | Status: Coming soon | Independent verification of scoped customer authority in the customer's environment, with local replay protection and signed execution evidence. In development; distinct from today's provider connection paths. |
| Database connections (BYOD) | Status: Planned | Planned customer-side database operations under scoped authority, starting with PostgreSQL. |
| RED API and SDK | Status: Planned | Planned interfaces for approved applications to request supported data operations under bounded authority. |
| Controlled agent authority | Status: Planned | Planned separate, scoped authority for AI agents and workloads, without reusing a person's unrestricted session. |
| Encrypted filename and folder metadata | Status: Planned | Protect names and structure in addition to contents. |
Environments
Storage environments.
AWS S3 is the generally available storage path today. Every other environment carries its own status.
AWS S3
- Status
- Status: Available today
- Note
- Generally available storage path
MinIO / S3-compatible
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Microsoft Azure Blob Storage
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Google Cloud Storage
- Status
- Status: Controlled pilot
- Note
- Implemented; enabled for selected deployments
Oracle Cloud Object Storage
- Status
- Status: Planned
- Note
- Direction
Cloudflare R2
- Status
- Status: Planned
- Note
- Direction
Private and on-premises infrastructure
- Status
- Status: Planned
- Note
- Direction
Databases
- Status
- Status: Planned
- Note
- Direction
| Environment | Status | Note |
|---|---|---|
| AWS S3 | Status: Available today | Generally available storage path |
| MinIO / S3-compatible | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Microsoft Azure Blob Storage | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Google Cloud Storage | Status: Controlled pilot | Implemented; enabled for selected deployments |
| Oracle Cloud Object Storage | Status: Planned | Direction |
| Cloudflare R2 | Status: Planned | Direction |
| Private and on-premises infrastructure | Status: Planned | Direction |
| Databases | Status: Planned | Direction |
Provider names describe the architecture and its direction. Inclusion does not imply partnership, endorsement, certification, or a current integration. Each environment carries its own status.
RED uses a Bring Your Own Storage (BYOS) model. Your organization connects RED to storage under its own control. Rhea does not provide, host, or operate customer storage.
Movement
Movement is two capabilities, not one.
Moving protected data between connected AWS S3 locations is a different operation from moving it across different providers, and the two do not share a status.
Movement between connected AWS S3 locations
- Status
- Status: Available today
- Note
- A move copies the protected data to the destination. The source object is not deleted by the move itself.
Movement across different providers
- Status
- Status: Planned
- Note
- Cross-provider movement is not available today
| Operation | Status | Note |
|---|---|---|
| Movement between connected AWS S3 locations | Status: Available today | A move copies the protected data to the destination. The source object is not deleted by the move itself. |
| Movement across different providers | Status: Planned | Cross-provider movement is not available today |
Classification evidence
What each status covers.
Availability is specific to a feature, deployment and execution mode. Existing provider code does not by itself establish a supported release or independent customer-controlled enforcement.
MinIO and S3-compatible storage
Controlled pilot
Controlled pilot, not general availability. This status does not establish the new customer-controlled execution architecture.
Microsoft Azure Blob Storage
Controlled pilot
Controlled pilot, not general availability. This status does not establish the new customer-controlled execution architecture.
Google Cloud Storage
Controlled pilot
Controlled pilot, not general availability. This status does not establish the new customer-controlled execution architecture.
Cloudflare R2, Oracle Cloud Object Storage, on-premises
Planned
These environments are planned and are not offered as generally available integrations.
Multiple customer-owned AWS S3 locations in one organization
Available today
RED holds cloud connections per organization as a list with one default rather than a single connection record, routes each document to a connection through folder and tag placement policy before encryption, and shows a connection selector during upload whenever more than one connection exists. Several AWS S3 locations can therefore be connected and used at the same time inside one organization. Reviewed in RED commit 114aa798.
Movement between connected AWS S3 locations
Available today
RED's cloud-operations movement path executes today between connected AWS S3 locations, with checking, transfer, verification and audit. The movement helpers implement copy-to-destination semantics; the source object is not deleted by the move itself, and that limitation is published next to the capability.
Movement across different providers
Planned
The movement path does not implement a cross-provider transfer between differing provider backends. Moving protected data from, for example, AWS S3 to Azure Blob Storage is not available today.
BYOD (Bring Your Own Database)
Planned
No database connector exists in the product. Every database integration statement on this site is product direction.
Rhea Key Android
Available today
A shipped Android client performs authentication, signing and approval against the same protocol as the web client.
Rhea Key iOS and Rhea ID
Coming soon
In development. No generally available client or service exists for either today.
Evidence reviewed against the read-only product snapshots RED c62cb0f5 and Rhea Key Web 06dd55e on 17 August 2026.
Not available today
What a reader could otherwise assume already exists.
These interfaces are not currently generally available. Public technical documentation will be published only when the corresponding integration surfaces are ready.
- Public RED API or SDK documentation
- Generally available application integration
- Generally available agent integration
- BYOD and database integrations
- Cross-provider movement of protected data
- Generally available storage beyond AWS S3
- Rhea ID
- Rhea Key iOS
- Encrypted filename and folder metadata