How DataCore Analytics Keeps Data Confidential
12 May 2026
Transfer research data to your project's encrypted storage.
Files are checksummed in your browser before anything is sent, then uploaded directly to project-scoped Google Cloud Storage. Data does not pass through our web server at any point.
Your browser computes a SHA-256 checksum for each file. Nothing has left your machine yet.
We issue a signed upload link valid for 30 minutes, scoped to your project alone.
Files upload directly to encrypted cloud storage over TLS, resuming automatically if the connection drops.
We re-compute checksums on arrival and confirm by email within two working days.
The browser requests a short-lived signed URL from our authorisation service, then uploads the bytes directly to Google Cloud Storage. Our web server never receives, buffers or stores your files. The signed link expires after 30 minutes and is scoped to a single object path inside your project's own prefix.
Transfers use TLS 1.3. Objects are encrypted at rest with Google-managed keys by default; customer-managed encryption keys are available for projects whose data governance requires them.
Uploads land in a project-scoped prefix that only your named analyst and the reviewing consultant can read. Every access is logged and the log is available to you on request. The storage bucket has public access permanently disabled and object versioning enabled.
Your browser computes a SHA-256 checksum before upload and it travels with the object as metadata. We recompute on arrival and compare. A mismatch means a corrupted transfer, and we ask you to resend that file rather than analysing it.
Data is retained for the period set out in your project agreement, then returned or securely deleted. Deletion is confirmed to you in writing. Lifecycle rules on the bucket enforce this automatically rather than relying on someone remembering.
For datasets in the multi-terabyte range, browser upload is rarely the right tool. We can provide gcloud storage or rclone credentials scoped to your project prefix, which will saturate your connection far more effectively. Ask your analyst.
If your data is already in Google Cloud Storage, AWS S3, Azure Blob, SRA, ENA or an institutional repository, do not download and re-upload it. Grant us read access to the location, or send the accessions, and we will pull it directly.
Uploads resume automatically after interruption — close the tab and return later if you need to. Where bandwidth makes transfer impractical, we can arrange encrypted physical media transfer; contact us to discuss it.
Please do not send research data by email or through consumer file-sharing links. Neither meets the access control and logging standards set out in our data handling policy.
