Security and governance

Built for controlled-access data.

Access is decided by the application on every request. Each institution's data sits behind its own boundary, in your own cloud account, in formats you can read without us.

Isolation

Each institution has its own boundary.

A tenant is the wall between one institution's data and another's. People, collections and storage belong to a tenant.

RequestSigned-in user

Every call carries an identity.

ApplicationAuthorization

Resolves which collections this person may read, then filters every query to them.

StorageTenant bucket + catalog

A separate bucket and catalog for each institution.

Separate storageEach tenant gets its own S3 bucket and its own Glue catalog database.
Collection-level filteringQueries always carry the list of collections the user may read. Nothing is filtered after the fact.
Membership is the boundaryAdministrators and curators are scoped to the tenants they belong to, not to the platform.
Access control

Four roles, scoped by tenant.

Collection access comes from ownership, membership or permission groups. Roles decide who administers the tenant around them.

RoleScope
Super AdminThe whole platform: tenants, users, roles, audit and platform settings.
Tenant AdminTheir own tenants: members, permission groups, access requests, approval policy and member quotas.
Data CuratorReview of collections and data structures in their own tenants.
UserThe collections they own, belong to, or reach through a permission group.
Permission groupsGrant a set of collections to a set of people, and let people request access through a queue.
Working versus publishedSeeing unreleased data is a separate permission from reading released data.
Every request

Permissions are checked when data moves, not just when a page opens.

File accessDownloads, previews and browser query files are authorized on each fetch against the person's current permissions.
Short-lived linksLinks to files are tied to the user and expire quickly. A deactivated account or a removed permission stops working on the next fetch.
Fail closedWhen access to an external grant cannot be updated, the old grant is removed rather than left in place.
Audit

A record you can review.

What is recordedUploads, previews, downloads, releases, retractions, permission changes and platform setting changes.
Configurable categoriesChoose which categories of activity are written to the log.
Who can read itAudit history is available to platform administrators.
Release controls

Nothing reaches readers without a decision.

Approval workflowsCollections and data structures can require approval by a curator. Each tenant sets its own policy.
Locked releasesA released file cannot be deleted or renamed. It can only be retracted, with a recorded reason.
Pinned snapshotsReleases, cohorts, findings and notebooks tag the exact data they used, so routine clean-up never removes it.
Your data

In your cloud account, in open formats.

Your AWS accountData lives in storage your institution controls.
Apache IcebergTabular data is stored as open Iceberg tables you can read with other tools, without us.
Storage lifecyclePublished copies are tagged so older data can move to cheaper storage automatically. Abandoned uploads clean themselves up.
Storage limitsQuotas per institution and per member stop one user from consuming a shared pool.
External access optional

Reach your own compute without opening the bucket.

Two opt-insThe institution and the collection owner must both allow reads from users' own AWS accounts. Data use terms can differ per dataset.
Only what they may already readGrants come from the same download rules the application uses. There is nothing extra to keep in sync.
Revocation in minutesA background pass re-derives every grant. A platform administrator can switch the whole feature off, and every grant is removed.
Off by default. It is enabled per deployment by a platform administrator.
Shared responsibility

Who handles what.

ScientHouseYour institution
Application access decisionsBuilds and enforces them on every request.Decides who belongs to which tenant, group and collection.
Storage and networkConfigures buckets, catalogs and lifecycle rules.Owns the AWS account and its organization-level controls.
Approval policyProvides the workflows and records decisions.Sets the policy and staffs the curator role.
Compliance reviewsAnswers questionnaires and walks your security team through the architecture.Determines what your program requires.

Bring your security team.

We will complete your institute's questionnaire and walk through the architecture with them.

Request a security review