Data
Rhea Data
The operating environment for protected data, permissions and everyday data workflows.
Available today
Data authority and operations infrastructure
Control who can access your organization's data and what they can do with it. Rhea Data brings protection, permissions and everyday data operations into one environment, connected to infrastructure you control.
Infrastructure access is not data authority.
People work in Rhea Data today. Rhea is extending the model to applications, AI agents and workloads across supported storage, databases and systems.

Rhea Holdings SRL
Rhea in the digital economy
Every new application creates another way to use organizational data. Rhea's direction is a shared layer for deciding which people, applications and AI agents may use that data, which operations they may perform and what evidence is recorded.
Keep the clouds, databases, business systems and security tools you choose. Rhea is building a common authority and operations model across supported systems, with Rhea Data as the environment people use to work with it.
People · Teams · Organizations
Applications · AI agents
Independent data authority and operations
Protect systems, identities and access.
CrowdStrike · Palo Alto Networks · Fortinet
Where organizational data is structured, analyzed and used.
Snowflake · Databricks · Oracle Database · Microsoft SQL Server · PostgreSQL · SAP · Salesforce · ServiceNow
Where organizational data is stored, processed and transported.
AWS · Microsoft Azure · Google Cloud · Oracle Cloud · Cloudflare
What the digital economy runs on.
Data centres · Networks · Servers · Devices
People · Teams · Organizations
Rhea Data — Protect · Organize · Authorize · Access · Share · Move · Audit
Protect systems, identities and access.
CrowdStrike · Palo Alto Networks · Fortinet
Where organizational data is structured, analyzed and used.
Snowflake · Databricks · Oracle Database · Microsoft SQL Server · PostgreSQL · SAP · Salesforce · ServiceNow
Where organizational data is stored, processed and transported.
AWS · Microsoft Azure · Google Cloud · Oracle Cloud · Cloudflare
What the digital economy runs on.
Data centres · Networks · Servers · Devices
Where does the data run?
Are the systems, workloads, endpoints and identities protected?
Who may make protected data readable, what may they do and what evidence remains?
Rhea's direction combines customer-owned authority, supported data operations and customer-side verification. It complements the infrastructure and security systems organizations already use; it does not replace their native controls.
Architectural direction—not company ranking.
Why Rhea is different
Rhea Data brings data work, permissions and recorded activity into one environment. Rhea's next architecture makes customer-owned authority independently enforceable in the customer's environment: Rhea coordinates the operation, while the customer-controlled connector checks whether it is authorized to run.
When controls are fragmented
Rhea's approach
Encryption protects content. Authorization defines permitted use. Rhea Data brings them into practical workflows; Rhea's customer-controlled architecture extends where that authority is enforced.
Storage access alone does not provide the document keys needed to read Rhea Data-protected content.
Protect, organize, authorize, access, share, move and audit through Rhea Data.
Connected AWS S3 locations can change without abandoning Rhea Data's protection and evidence model. Cross-provider movement is Planned.
Who Rhea Data is for
Rhea Data is for organizations that need to protect, organize, collect and share important information on storage they control, with defined access and a record of activity.
See Rhea Data by buyer and decision momentWhen Rhea Data becomes relevant
Current prerequisite: customer-owned AWS S3 for the available public storage path.
What Rhea Data makes easier
Within Rhea Data's available AWS S3 path, these operations share one protection, authority and evidence model. Provider-specific availability is documented on Product Status.
Encrypt file content on the device before connected storage receives it.
Bring documents, folders and Secure Notes into a structured environment.
Set permissions and require approvals for supported sensitive actions.
Open and download protected documents through Rhea Data's authorization flow.
Give defined members access to protected files and folders.
Copy protected documents between connected AWS S3 locations and update their location in Rhea Data.
Review recorded access, approvals, administration and cryptographic activity.
Named recipients receive access under the organization's policy, not a link that outlives the relationship.
Inbound material enters the organization's protection model at the point of collection.
Rhea Data handles checking, transfer, verification and audit; protection and authority do not change.
Security by trust boundary
Rhea Data encrypts file content before storage and keeps plaintext document decryption keys outside its backend. Metadata, provider credentials and the delivered web client have different trust boundaries, explained below.
Connected storage receives encrypted objects only. Document keys never reach it, so stored content stays encrypted.
The web client Rhea delivers is its own trust boundary: a compromised delivery can affect future uploads and future authorized opens.
Plaintext exists where authority already lives. Control of that device means seeing what its holder can see.
An attacker with full bucket access obtains ciphertext and object layout. Files do not open: the data keys are not in the bucket, and tampering with chunks or the manifest fails authentication rather than producing wrong plaintext.
An attacker reads operational metadata — including filenames and folder names — plus wrapped key material they cannot unwrap. No document key can be recovered, because the unwrapping key is derived on your device from a wallet signature that is never stored.
An attacker gains the database plus Rhea's server-held secrets, which include the key protecting your storage credentials. They can therefore reach your bucket and take ciphertext, and they can serve a modified client application to future users. They still cannot decrypt existing protected content, because no server-side path to a document key exists.
Everything that user is authorized to open can be read, because decryption legitimately happens on their device. Their authority can be revoked, and their actions remain in the audit record. This is the strongest reason to scope authority narrowly.
The attacker can perform administration — membership, policy and configuration changes — and those changes are recorded. They cannot decrypt documents for which the administrator holds no wrapped key, because administration does not confer readability.
A single guardian's Recovery Kit is not sufficient. Recovery requires the configured threshold of guardians, each providing a signed, single-use consent, with reconstruction happening only in the initiating administrator's browser.
Data · Access · Identity
Data
The operating environment for protected data, permissions and everyday data workflows.
Available today
Access
Cryptographic authentication and approval for supported Rhea workflows, on web and Android.
Web and Android available · iOS coming soon
Open Rhea Key Web (opens Rhea application in a new tab)Identity
Verified identity attributes for use in authorization decisions. In development.
Coming soon
Read morePlanned developer interfaces will extend supported operations to applications, AI agents and workloads. Database connectivity and broader provider support follow the published product scope. See complete product status.
Pricing
Rhea Data does not charge for owning your storage. Standard plans combine a monthly organization fee with the amount of data Rhea Data processes and the operations it performs.
For requirements outside the standard plans.