Data authority and operations infrastructure

One layer above all data.

Control who can access your organization's data and what they can do with it. Rhea Data brings protection, permissions and everyday data operations into one environment, connected to infrastructure you control.

Infrastructure access is not data authority.

People work in Rhea Data today. Rhea is extending the model to applications, AI agents and workloads across supported storage, databases and systems.

rhea.red
Rhea Data Command Center showing operational usage, activity charts and organizational metrics.
Rhea Data Command Center — operational usage and organizational visibility. Example data is synthetic.

Rhea Holdings SRL

Rhea in the digital economy

The authority layer for a connected digital economy.

Every new application creates another way to use organizational data. Rhea's direction is a shared layer for deciding which people, applications and AI agents may use that data, which operations they may perform and what evidence is recorded.

Keep the clouds, databases, business systems and security tools you choose. Rhea is building a common authority and operations model across supported systems, with Rhea Data as the environment people use to work with it.

People · Teams · Organizations

Applications · AI agents

RHEA

Independent data authority and operations

Cybersecurity and identity

Data platforms, databases and business systems

Cloud, storage, compute and edge

Physical digital infrastructure

People · Teams · Organizations

Applications · AI agents

Independent data authority and operations

Rhea Data — Protect · Organize · Authorize · Access · Share · Move · Audit

Cybersecurity and identity

Protect systems, identities and access.

CrowdStrike · Palo Alto Networks · Fortinet

Data platforms, databases and business systems

Where organizational data is structured, analyzed and used.

Snowflake · Databricks · Oracle Database · Microsoft SQL Server · PostgreSQL · SAP · Salesforce · ServiceNow

Cloud, storage, compute and edge

Where organizational data is stored, processed and transported.

AWS · Microsoft Azure · Google Cloud · Oracle Cloud · Cloudflare

Physical digital infrastructure

What the digital economy runs on.

Data centres · Networks · Servers · Devices

Cloud and infrastructure

Where does the data run?

Cybersecurity and identity

Are the systems, workloads, endpoints and identities protected?

Rhea

Who may make protected data readable, what may they do and what evidence remains?

Rhea's direction combines customer-owned authority, supported data operations and customer-side verification. It complements the infrastructure and security systems organizations already use; it does not replace their native controls.

Architectural direction—not company ranking.

Company names illustrate the surrounding technology landscape. They do not imply partnership, endorsement or current Rhea Data integration. Product Status identifies current availability.

Why Rhea is different

Your infrastructure holds the data. Your organization defines the authority.

Rhea Data brings data work, permissions and recorded activity into one environment. Rhea's next architecture makes customer-owned authority independently enforceable in the customer's environment: Rhea coordinates the operation, while the customer-controlled connector checks whether it is authorized to run.

When controls are fragmented

  • Separate connections for each workflow
  • Permissions repeated across systems
  • Different ways to perform the same task
  • Activity scattered across tools
  • More coordination when systems change

Rhea's approach

  • One Rhea Data operating environment
  • Data protection and permissions together
  • Supported operations through a common model
  • Recorded activity in the same environment
  • An architecture built for extension

Encryption protects content. Authorization defines permitted use. Rhea Data brings them into practical workflows; Rhea's customer-controlled architecture extends where that authority is enforced.

One authority model

Storage access alone does not provide the document keys needed to read Rhea Data-protected content.

One operating environment

Protect, organize, authorize, access, share, move and audit through Rhea Data.

Continuity across change

Connected AWS S3 locations can change without abandoning Rhea Data's protection and evidence model. Cross-provider movement is Planned.

Who Rhea Data is for

For teams responsible for data that matters.

Rhea Data is for organizations that need to protect, organize, collect and share important information on storage they control, with defined access and a record of activity.

See Rhea Data by buyer and decision moment

When Rhea Data becomes relevant

  • Infrastructure administration must not equal permission to read.
  • A person's future access must end when their role or relationship changes.
  • Important files are still collected through email or loose links.
  • The organization needs evidence of who accessed or approved what.
  • Storage locations need to change without rebuilding the authority model.
  • Protected files must be stored in customer-owned infrastructure.

Current prerequisite: customer-owned AWS S3 for the available public storage path.

What Rhea Data makes easier

Seven operations on organizational data, in one environment.

Within Rhea Data's available AWS S3 path, these operations share one protection, authority and evidence model. Provider-specific availability is documented on Product Status.

  • Protect

    Encrypt file content on the device before connected storage receives it.

  • Organize

    Bring documents, folders and Secure Notes into a structured environment.

  • Authorize

    Set permissions and require approvals for supported sensitive actions.

  • Access

    Open and download protected documents through Rhea Data's authorization flow.

  • Share

    Give defined members access to protected files and folders.

  • Move

    Copy protected documents between connected AWS S3 locations and update their location in Rhea Data.

  • Audit

    Review recorded access, approvals, administration and cryptographic activity.

What Rhea Data is responsible for — six areasData, access, security, governance, infrastructure and operations.
  • DataDocuments, folders, secure notes, classification, retention.
  • AccessRoles, permissions, sharing, file requests, approvals.
  • SecurityClient-side protection, key custody, sessions, alerts, recovery.
  • GovernancePolicy, evidence, retention, audit review.
  • InfrastructureStorage connections, providers, health, movement.
  • OperationsMembers, usage, administration, system state.
Three workflows, as they run in Rhea Data todayShare a document, collect a document, change storage.
  • Share a document

    1. 01Select data
    2. 02Authorize
    3. 03Share

    Named recipients receive access under the organization's policy, not a link that outlives the relationship.

  • Collect a document

    1. 01Request data
    2. 02Receive
    3. 03Organize

    Inbound material enters the organization's protection model at the point of collection.

  • Change storage

    1. 01Select data
    2. 02Choose destination
    3. 03Move

    Rhea Data handles checking, transfer, verification and audit; protection and authority do not change.

Security by trust boundary

Storage access alone should not mean readable content.

Rhea Data encrypts file content before storage and keeps plaintext document decryption keys outside its backend. Metadata, provider credentials and the delivered web client have different trust boundaries, explained below.

  • Stored ciphertext

    Connected storage receives encrypted objects only. Document keys never reach it, so stored content stays encrypted.

  • Delivered client

    The web client Rhea delivers is its own trust boundary: a compromised delivery can affect future uploads and future authorized opens.

  • Authorized device

    Plaintext exists where authority already lives. Control of that device means seeing what its holder can see.

See all compromise scenariosStorage provider, Rhea's database, Rhea's backend, a user device — with what each does and does not reach.
  • Your storage provider is compromised

    An attacker with full bucket access obtains ciphertext and object layout. Files do not open: the data keys are not in the bucket, and tampering with chunks or the manifest fails authentication rather than producing wrong plaintext.

    Exposed
    Ciphertext, object sizes, object counts
    Protected
    File contents, document keys
  • Rhea's database is compromised

    An attacker reads operational metadata — including filenames and folder names — plus wrapped key material they cannot unwrap. No document key can be recovered, because the unwrapping key is derived on your device from a wallet signature that is never stored.

    Exposed
    Filenames, sizes, timestamps, audit records, wrapped keys as ciphertext
    Protected
    File contents, document keys, recovery shares
  • Rhea's backend is compromised

    An attacker gains the database plus Rhea's server-held secrets, which include the key protecting your storage credentials. They can therefore reach your bucket and take ciphertext, and they can serve a modified client application to future users. They still cannot decrypt existing protected content, because no server-side path to a document key exists.

    Exposed
    Storage credentials, all metadata, the ability to serve client code
    Protected
    Existing protected file contents, document keys
  • A user's device is compromised

    Everything that user is authorized to open can be read, because decryption legitimately happens on their device. Their authority can be revoked, and their actions remain in the audit record. This is the strongest reason to scope authority narrowly.

    Exposed
    Files that user is authorized to decrypt
    Protected
    Documents for which that user holds no wrapped key
  • An organization administrator is compromised

    The attacker can perform administration — membership, policy and configuration changes — and those changes are recorded. They cannot decrypt documents for which the administrator holds no wrapped key, because administration does not confer readability.

    Exposed
    Organization configuration, membership, metadata
    Protected
    Contents of documents not wrapped to that administrator
  • A guardian is compromised

    A single guardian's Recovery Kit is not sufficient. Recovery requires the configured threshold of guardians, each providing a signed, single-use consent, with reconstruction happening only in the initiating administrator's browser.

    Exposed
    One recovery share, if the passphrase is also obtained
    Protected
    The organization key, below the guardian threshold

Data · Access · Identity

One system family, three responsibilities.

Identity

Rhea ID

Verified identity attributes for use in authorization decisions. In development.

Coming soon

Read more

Planned developer interfaces will extend supported operations to applications, AI agents and workloads. Database connectivity and broader provider support follow the published product scope. See complete product status.

Pricing

Your infrastructure stays yours. Pricing follows Rhea Data usage.

Rhea Data does not charge for owning your storage. Standard plans combine a monthly organization fee with the amount of data Rhea Data processes and the operations it performs.

Launch

€399

/ organization / month

€0.60

/ GiB processed

View plan in Rhea Data

Growth

€1,499

/ organization / month

€0.15

/ GiB processed

View plan in Rhea Data

Expand

€2,799

/ organization / month

€0.08

/ GiB processed

View plan in Rhea Data

Scale

€4,999

/ organization / month

€0.05

/ GiB processed

View plan in Rhea Data

Custom

For requirements outside the standard plans.

Contact Rhea
  • Operations are billed at €0.01 per 1,000 operations.
  • Only relay-processed data is charged at 10× the selected plan's data rate. The relay portion is charged once, not at both the standard and relay rate.
  • Customer-owned storage-provider charges are separate and paid directly by the customer.