Security & Compliance

Compliance isn't a feature.
It's the architecture.

Every myDRE deployment runs inside your own Azure subscription, so your data never leaves your tenant. We add the governance layer on top.

NIS2-SC30 Ready ISO 27001 Certified
Regular Pentest Independently tested
Public ISMS Transparent by default
GDPR Compliant by design
Azure Your tenant, your control

Data never leaves your Azure tenant

myDRE runs inside your own Azure subscription. No shared infrastructure. No data movement to a third-party cloud.

Full audit log on every action

Every workspace action, data access, and user change is logged. Demonstrable duty of care for your DPO, always.

Secure data ingress & egress (Airlock)

Controlled data in and out through an airlocked review process. Sensitive data cannot leave without approval.

Access Reviews

Periodic access reviews are built into every workspace. Owners reconfirm who still needs access, and each review is recorded for your DPO and auditor.

Role-based access

Everyone has exactly the access their role requires, and nothing more. Accountable, privileged, and regular members are separated by design.

No inbound internet by default

Workspaces are closed by default: no inbound internet connection is possible. Researchers reach their environment through myDRE, never through an open port.

FAQ

General

What is myDRE and who is it designed for? +

myDRE (by anDREa) is a secure, automated Trusted Research Environment (TRE) built on Microsoft Azure. Created by and for research institutions, such as University Medical Centers, universities, top clinical hospitals, and knowledge institutes, it enables safe data sharing and collaboration without IT, privacy, or compliance hassles.

What software, AI tools, and data sources can I use within myDRE? +

myDRE is data & tool agnostic and supports both Windows and Linux Virtual Machines (VMs). You can use:

  • Data Analysis & Statistics: R/RStudio, Python, MATLAB, SPSS, STATA.
  • AI & Machine Learning: ChatGPT, Claude.ai, OpenAI, Gemini, HuggingFace, PyTorch, TensorFlow.
  • Data Management & EDC: Castor EDC, ZorgTTP, Research Drive.

Security, Privacy & Governance

How does myDRE guarantee information security and privacy (GDPR)? +

anDREa is ISO/IEC 27001:2023 certified and holds the NIS2-SC30 quality mark. The platform provides out-of-the-box compliance with GDPR obligations through strict Role-Based Access Control (RBAC), periodic access reviews, and controlled data import and export processes (ingress/egress).

Does our organization retain ownership and control of its data? +

Yes. Your data remains fully under your organization's control within your own Microsoft Azure tenant at all times. There is zero risk of data spillover between myDRE and your institution's core systems.

Implementation, Pricing & Access

How fast can myDRE be implemented, and how does pricing work? +
  • Speed: Technical Azure setup requires a one-time effort of about 20 minutes. Within a few days, your tenancy is configured and your support team is trained. Once set up, deploying a new workspace takes under 10 minutes.
  • Pricing: Transparent pay-per-use model (you pay directly for actual Azure compute and storage consumption; median cost is ~€11 per workspace) plus a tiered workspace license fee based on active workspaces.
How do I access myDRE, and what should I do if my workspace is missing? +

Log in at https://mydre.org using your myDRE account and Multi-Factor Authentication (MFA). If your workspace is missing:

  • Ensure you logged in with your myDRE account.
  • Verify whether you are invited to the workspace.
  • If the issue persists, submit a support ticket via support.mydre.org.

Roles, Usage & Data

What are the user roles and permissions within a myDRE Workspace? +

Using Role-Based Access Control (RBAC), myDRE defines four roles:

  • Accountable Member: (e.g., PI or Department Head) Oversees costs, workspace management, and bi-annual access reviews. Limited to one per workspace.
  • Privileged Member: Workspace administrator (can create VMs, manage user access, and submit egress requests).
  • Advanced Member: Can perform elevated technical actions and data processing inside assigned VMs.
  • Restricted Member: Standard researcher with access restricted to specific VMs and datasets.
How do I start a Virtual Machine (VM) and install additional software? +

Navigate to the Virtual Machines tab inside your workspace, click Start on your assigned VM, and then click Connect (via RDP).

  • Auto-shutdown: To optimize cloud costs, VMs automatically shut down by default at 19:00 (UTC+1). Privileged Members can adjust or disable auto-shutdown for overnight processes.
  • Installing Software: Most tenants have created templates users can choose that come with pre-installed software or are available via the local software store (Chocolatey).
How does data import and export (Ingress/Egress) work? +
  • Import (Ingress): Data can be uploaded directly to the central, encrypted Azure Fileshare of your workspace or connected via Castor, Research Drive, or ZorgTTP.

We also provide a guided file upload system that helps collaborating researchers receive data from multiple partners in an organized, auditable way: myDRE Dropzone.

  • Export (Egress): To prevent data leaks, exporting files outside the workspace is strictly controlled and requires formal approval (an egress ticket) from a Privileged or Accountable Member.

Collaboration & Support

Can I collaborate with external/international partners? +
  • Collaboration: Yes, myDRE supports cross-institutional and international multi-center studies. External researchers receive role-restricted access to specific workspaces without compromising global environment safety.
Where can I find support? +
  • Support: Access step-by-step guides and manuals in the knowledge base at support.mydre.org, or submit a support ticket directly to your local Core Support Team. And also our myDRE support team is always available.

Ready to see how myDRE fits your organization?!

Let's talk. Information and support is always personal.

Let's talk