Enabling Trusted, Sensitive Data Research in AWS for a Leading U.S. Research University

Overview

A leading research university moved off a SaaS-only research platform to Research Gateway Enterprise on AWS. The result: a governed Trusted Research Environment with controlled data ingress and egress, federated identity for both internal and external collaborators, and standardized secure research workspaces.

INDUSTRY
Healthcare & Life Sciences - Academic Medical Centers
SERVICES/PLATFORMS
Research Gateway

A leading U.S. research university sought to establish a modern Trusted Research Environment (TRE) capable of supporting sensitive research workloads, external research collaborations, and future compliance-driven research initiatives.

Having previously evaluated Research Gateway in a SaaS deployment model, the university selected Research Gateway Enterprise to gain greater control over research infrastructure, secure data management, federated identity integration, and trusted research workflows.

Working together, RelevanceLab and the university implemented a Secure Research Environment (SRE) architecture that enables controlled data ingress, secure researcher workspaces, governed data egress, and project-level isolation while maintaining a self-service experience for researchers.

The resulting platform provides a scalable foundation for secure research, trusted collaboration, and future expansion into regulated research programs.

Healthcare Research Case Study cover
Case Study · PDF

Trusted Research Environments for Sensitive University Research Data

A deep dive into how Research Gateway Enterprise delivers governed, self-service research workspaces, controlled data ingress and egress, and federated identity for internal and external collaborators on AWS.

View the Full Case Study

Business Challenges

The university faced several strategic challenges while expanding its cloud research capabilities:

01

Protecting Sensitive Research Data

Researchers required access to controlled datasets with secure data access, project-level isolation, controlled data movement, protection against unauthorized downloads, and fully auditable research workflows.

02

Supporting External Collaborators

Research initiatives involved collaborators outside the university, requiring federated identity, SAML-based authentication, secure onboarding, and simplified access management without increasing IAM complexity.

03

Enterprise Governance Requirements

The institution required complete ownership of AWS infrastructure, enterprise security integration, flexible authorization models, HIPAA-ready architecture, and standardized research workspaces under centralized governance.

Solution

Relevance Lab implemented Research Gateway Enterprise as the foundation for the university's Trusted Research Environment strategy.

The deployment combined:

Secure Research Environments (TRE)

Research Gateway Enterprise established isolated Trusted Research Environments with built-in security controls.

  • Controlled data ingress
  • Controlled data egress
  • Secure Linux desktops
  • Project-level storage
  • Encrypted communications
  • Research project isolation
Federated Identity Integration

AWS Cognito and SAML authentication enabled seamless access for both internal researchers and external collaborators while simplifying administration.

  • AWS Cognito integration
  • SAML authentication
  • External collaborator access
  • Simplified authorization model
  • Centralized identity management
Standardized Research Workspaces

A Golden AMI strategy delivered consistent research environments across every project.

  • Rocky Linux workspaces
  • Amazon DCV secure desktops
  • RStudio
  • JupyterLab
  • Docker-enabled environments
  • Standardized researcher experience

Trusted Research Environment Architecture

The Secure Research Environment was designed around a governed data lifecycle.

Key Capabilities

Trusted Research Controls

  • Controlled Data Ingress
  • Controlled Data Egress
  • Data Steward Approval Workflow
  • Secure Research Desktops
  • Download Restrictions
  • Project-Level Isolation
  • Audit Trail & Monitoring

Identity Federation

  • AWS Cognito Integration
  • SAML Authentication
  • External Collaborator Access
  • Researcher Self-Service Access
  • Simplified Authorization Model

Research Platform Services

  • Research Gateway Enterprise
  • AWS Service Catalog
  • Amazon EC2
  • Amazon S3
  • Amazon Cognito
  • AWS Lambda
  • AWS Lake Formation
  • AWS Cost Management

Business Outcomes

Improved Research Security

  • Protected sensitive research data
  • Controlled ingress and egress workflows
  • Secure isolated environments
  • Complete audit trails

Better Researcher Experience

  • Self-service workspace provisioning
  • No deep cloud expertise required
  • Rapid project onboarding
  • Consistent research environments

Simplified Collaboration

  • Federated authentication support
  • Internal researcher access
  • External collaborator integration
  • Streamlined identity management

Operational Consistency

  • Standardized workspace images
  • Reduced administration effort
  • Simplified maintenance processes
  • Centralized governance controls

Future-Ready Platform

  • Trusted Research Environments
  • HIPAA-aligned research
  • Regulated data programs
  • Advanced governance initiatives
  • Hybrid cloud research computing

Customer Perspective

Research Gateway Enterprise provided a scalable foundation for trusted research by combining secure research environments, federated identity integration, and self-service researcher experiences while maintaining strong governance and security controls.

HEALTHCARE RESEARCH CASE STUDY

Give Your Researchers a Faster, More Secure Way to Work.

See how Relevance Lab helps universities and research institutions balance self-service access with strict data governance using Research Gateway Enterprise.

Tags

No items found.