Data & security
Governance designed in, not added on.
MRB handles academic, research and potentially health-related information. This page describes how the platform is designed to support responsible data governance.
This overview describes design intent and controls. It is not a certification or a statement of regulatory compliance. Specific technical and contractual commitments are set out in each institution's agreement.
Access
People see only what their role permits.
- Built with controls for role-based access and least-privilege permissions
- Users belong to an institution; access is scoped to that institution
- Institution-specific access and retention rules
Traceability
Critical actions leave a record.
- Audit trail for critical workflows: who created, edited, reviewed or approved, and when
- Version history for protocols and documents
- Decision history for ethics review
Research data
Collect less, protect what is collected.
- Data minimisation: direct identifiers are not collected unless genuinely required
- Study data use coded, non-identifying research IDs where data capture is used
- Consent and ethics status are linked to study data where applicable
- Designed to support encryption of data in transit and at rest
- Backup, disaster recovery and continuity are part of deployment planning
AI
Assistance is separate from authority.
- AI output is shown with its source context
- Reviewers accept, edit or reject each suggestion
- Scientific and ethical decisions remain with authorised people and committees
Regulated work
Clinical trials are handled separately.
Validation and documentation expectations for regulated clinical-trial modules are addressed separately from general academic workflows, within the My Trial Board ecosystem.