Sensitive Data Research in AWS Cloud with Relevance Lab Research Gateway

Overview

A leading research university replaced a SaaS-only research platform with Research Gateway Enterprise on AWS, gaining a governed Trusted Research Environment with controlled data ingress and egress, federated identity for internal and external collaborators, and standardized secure research workspaces.

INDUSTRY
Healthcare & Life Sciences - Academic Medical Centers
SERVICES/PLATFORMS
Research Gateway

The university sought to establish a modern Trusted Research Environment (TRE) capable of supporting sensitive research workloads, external research collaborations, and future compliance-driven research initiatives.

Having previously evaluated Research Gateway in a SaaS deployment model, the university selected Research Gateway Enterprise to gain greater control over research infrastructure, secure data management, federated identity integration, and trusted research workflows.

Working together, Relevance Lab and the university implemented a Secure Research Environment (SRE) architecture that enables controlled data ingress, secure researcher workspaces, governed data egress, and project-level isolation while maintaining a self-service experience for researchers.

The resulting platform provides a scalable foundation for secure research, trusted collaboration, and future expansion into regulated research programs.

Case Study Cover
CASE STUDY • PDF

Trusted Research Environment Blueprint

Explore the Trusted Research Environment architecture, Research Gateway deployment, controlled data ingress and egress workflows, federated identity integration, standardized research workspaces, governance framework, implementation approach, and business outcomes behind this secure research environment.

View the Full Case Study →

Business Challenges

The university faced several strategic challenges while expanding its cloud research capabilities:

🔒

Protecting Sensitive Research Data

Secure, controlled, and auditable access to research datasets, with isolation between projects and protection against unauthorized downloads.

🤝

Supporting External Collaborators

Federated identities, SAML-based authentication, and simplified onboarding for external researchers — without added IAM complexity.

🏛️

Enterprise Governance Requirements

Full ownership of AWS infrastructure, flexible authorization models, and a future-ready, HIPAA-aligned architecture.

Solution

Relevance Lab implemented Research Gateway Enterprise as the foundation for the university's Trusted Research Environment strategy.

The deployment combined:

Secure Research Environments (TRE)

Isolated project workspaces with controlled data ingress and egress, secure Linux desktops, project-level storage, and encrypted communication throughout.

Federated Identity Integration

Authentication integrated through AWS Cognito and SAML providers for internal and external researchers, with authorization managed directly within Research Gateway.

Research Workspace Standardization

A Golden AMI strategy featuring Rocky Linux workspaces, Amazon DCV secure desktops, RStudio, JupyterLab, and Docker-enabled environments for a consistent researcher experience.

Trusted Research Environment Architecture

The Secure Research Environment was designed around a governed data lifecycle.

Controlled Data Ingress

Research data enters the environment only through approved workflows. Every submission is verified through source validation, metadata checks, malware scanning, project registration, and audit logging before becoming available for research. Direct uploads are not permitted.

Secure Research Workspaces

Researchers work within isolated environments featuring secure desktops, dedicated storage, network isolation, and end-to-end encryption. Internet access and direct data downloads are restricted, ensuring sensitive research data remains protected throughout the project lifecycle.

Controlled Data Egress

Research outputs leave the environment only after formal review and approval. Data stewards validate requests, record approvals, and release only authorized results, ensuring governance, compliance, and complete protection of sensitive research data.

Business Outcomes

01

Improved Research Security

Sensitive research data remained protected through controlled data ingress and egress workflows while researchers operated within secure, isolated environments.

02

Better Researcher Experience

Researchers could rapidly provision and use secure workspaces through a self-service model without requiring deep cloud expertise.

03

Simplified Collaboration

Federated authentication enabled secure collaboration between internal and external researchers while simplifying identity and access management.

04

Operational Consistency

Standardized research workspaces reduced administration effort, simplified ongoing platform management, and delivered a consistent researcher experience across projects.

05

Future-Ready Research Platform

Established a scalable foundation for Trusted Research Environments, HIPAA-aligned research, regulated data programs, advanced governance, and hybrid cloud research computing.

Research Gateway: The Foundation for Trusted Research

Research Gateway provides a secure foundation for Trusted Research Environments on AWS, enabling governed data access, standardized research workspaces, federated identity, and self-service provisioning. It helps research organizations accelerate collaboration while maintaining security, compliance, and operational control.

TRUSTED RESEARCH ENVIRONMENT CASE STUDY

Planning a Secure Research Environment for Sensitive Data?

Discover how Relevance Lab Research Gateway helps universities, research institutions, healthcare organizations, and government agencies build secure Trusted Research Environments on AWS. Enable controlled data ingress and egress, federated identity, standardized research workspaces, and governed collaboration for sensitive and regulated research projects.

Tags

No items found.