The university sought to establish a modern Trusted Research Environment (TRE) capable of supporting sensitive research workloads, external research collaborations, and future compliance-driven research initiatives.
Having previously evaluated Research Gateway in a SaaS deployment model, the university selected Research Gateway Enterprise to gain greater control over research infrastructure, secure data management, federated identity integration, and trusted research workflows.
Working together, Relevance Lab and the university implemented a Secure Research Environment (SRE) architecture that enables controlled data ingress, secure researcher workspaces, governed data egress, and project-level isolation while maintaining a self-service experience for researchers.
The resulting platform provides a scalable foundation for secure research, trusted collaboration, and future expansion into regulated research programs.
CASE STUDY • PDF
Trusted Research Environment Blueprint
Explore the Trusted Research Environment architecture, Research Gateway deployment,
controlled data ingress and egress workflows, federated identity integration,
standardized research workspaces, governance framework, implementation approach,
and business outcomes behind this secure research environment.
View the Full Case Study →
Business Challenges
The university faced several strategic challenges while expanding its cloud research capabilities:
🔒
Protecting Sensitive Research Data
Secure, controlled, and auditable access to research datasets, with isolation between projects and protection against unauthorized downloads.
🤝
Supporting External Collaborators
Federated identities, SAML-based authentication, and simplified onboarding for external researchers — without added IAM complexity.
🏛️
Enterprise Governance Requirements
Full ownership of AWS infrastructure, flexible authorization models, and a future-ready, HIPAA-aligned architecture.
Solution
Relevance Lab implemented Research Gateway Enterprise as the foundation for the university's Trusted Research Environment strategy.
The deployment combined:
Secure Research Environments (TRE)
Isolated project workspaces with controlled data ingress and egress,
secure Linux desktops, project-level storage, and encrypted
communication throughout.
Federated Identity Integration
Authentication integrated through AWS Cognito and SAML providers
for internal and external researchers, with authorization managed
directly within Research Gateway.
Research Workspace Standardization
A Golden AMI strategy featuring Rocky Linux workspaces, Amazon DCV
secure desktops, RStudio, JupyterLab, and Docker-enabled environments
for a consistent researcher experience.
Trusted Research Environment Architecture
The Secure Research Environment was designed around a governed data lifecycle.
Controlled Data Ingress
Research data enters the environment only through approved workflows.
Every submission is verified through source validation, metadata checks,
malware scanning, project registration, and audit logging before becoming
available for research. Direct uploads are not permitted.
Secure Research Workspaces
Researchers work within isolated environments featuring secure desktops,
dedicated storage, network isolation, and end-to-end encryption. Internet
access and direct data downloads are restricted, ensuring sensitive
research data remains protected throughout the project lifecycle.
Controlled Data Egress
Research outputs leave the environment only after formal review and
approval. Data stewards validate requests, record approvals, and release
only authorized results, ensuring governance, compliance, and complete
protection of sensitive research data.
Business Outcomes
01
Improved Research Security
Sensitive research data remained protected through controlled data ingress and
egress workflows while researchers operated within secure, isolated environments.
02
Better Researcher Experience
Researchers could rapidly provision and use secure workspaces through a
self-service model without requiring deep cloud expertise.
03
Simplified Collaboration
Federated authentication enabled secure collaboration between internal and
external researchers while simplifying identity and access management.
04
Operational Consistency
Standardized research workspaces reduced administration effort,
simplified ongoing platform management, and delivered a consistent
researcher experience across projects.
05
Future-Ready Research Platform
Established a scalable foundation for Trusted Research Environments,
HIPAA-aligned research, regulated data programs, advanced governance,
and hybrid cloud research computing.
Research Gateway: The Foundation for Trusted Research
Research Gateway provides a secure foundation for Trusted Research Environments on AWS, enabling governed data access, standardized research workspaces, federated identity, and self-service provisioning. It helps research organizations accelerate collaboration while maintaining security, compliance, and operational control.
TRUSTED RESEARCH ENVIRONMENT CASE STUDY
Planning a Secure Research Environment for Sensitive Data?
Discover how Relevance Lab Research Gateway helps universities, research institutions,
healthcare organizations, and government agencies build secure Trusted Research
Environments on AWS. Enable controlled data ingress and egress, federated identity,
standardized research workspaces, and governed collaboration for sensitive and
regulated research projects.