Security and governance
Built for controlled-access data.
Access is decided by the application on every request. Each institution's data sits behind its own boundary, in your own cloud account, in formats you can read without us.
Isolation
Each institution has its own boundary.
A tenant is the wall between one institution's data and another's. People, collections and storage belong to a tenant.
RequestSigned-in user
Every call carries an identity.
ApplicationAuthorization
Resolves which collections this person may read, then filters every query to them.
StorageTenant bucket + catalog
A separate bucket and catalog for each institution.
Separate storageEach tenant gets its own S3 bucket and its own Glue catalog database.
Collection-level filteringQueries always carry the list of collections the user may read. Nothing is filtered after the fact.
Membership is the boundaryAdministrators and curators are scoped to the tenants they belong to, not to the platform.
Access control
Four roles, scoped by tenant.
Collection access comes from ownership, membership or permission groups. Roles decide who administers the tenant around them.
| Role | Scope |
|---|---|
| Super Admin | The whole platform: tenants, users, roles, audit and platform settings. |
| Tenant Admin | Their own tenants: members, permission groups, access requests, approval policy and member quotas. |
| Data Curator | Review of collections and data structures in their own tenants. |
| User | The collections they own, belong to, or reach through a permission group. |
Permission groupsGrant a set of collections to a set of people, and let people request access through a queue.
Working versus publishedSeeing unreleased data is a separate permission from reading released data.
Every request
Permissions are checked when data moves, not just when a page opens.
File accessDownloads, previews and browser query files are authorized on each fetch against the person's current permissions.
Short-lived linksLinks to files are tied to the user and expire quickly. A deactivated account or a removed permission stops working on the next fetch.
Fail closedWhen access to an external grant cannot be updated, the old grant is removed rather than left in place.
Audit
A record you can review.
What is recordedUploads, previews, downloads, releases, retractions, permission changes and platform setting changes.
Configurable categoriesChoose which categories of activity are written to the log.
Who can read itAudit history is available to platform administrators.
Release controls
Nothing reaches readers without a decision.
Approval workflowsCollections and data structures can require approval by a curator. Each tenant sets its own policy.
Locked releasesA released file cannot be deleted or renamed. It can only be retracted, with a recorded reason.
Pinned snapshotsReleases, cohorts, findings and notebooks tag the exact data they used, so routine clean-up never removes it.
Your data
In your cloud account, in open formats.
Your AWS accountData lives in storage your institution controls.
Apache IcebergTabular data is stored as open Iceberg tables you can read with other tools, without us.
Storage lifecyclePublished copies are tagged so older data can move to cheaper storage automatically. Abandoned uploads clean themselves up.
Storage limitsQuotas per institution and per member stop one user from consuming a shared pool.
External access optional
Reach your own compute without opening the bucket.
Two opt-insThe institution and the collection owner must both allow reads from users' own AWS accounts. Data use terms can differ per dataset.
Only what they may already readGrants come from the same download rules the application uses. There is nothing extra to keep in sync.
Revocation in minutesA background pass re-derives every grant. A platform administrator can switch the whole feature off, and every grant is removed.
Off by default. It is enabled per deployment by a platform administrator.
Bring your security team.
We will complete your institute's questionnaire and walk through the architecture with them.