Skip to main content
Overview

What is CHORUS

Concept

CHORUS is a Secure Processing Environment (SPE) for research and AI on sensitive data. Instead of sending data out to wherever the analysis happens, CHORUS brings the tools, the compute, and the researchers to the data - and keeps the whole thing under institutional control.

In short

You work on sensitive data inside a protected environment, through your browser, with nothing copied to your own machine. Each project gets its own isolated workspace. What comes in and what goes out is decided by people, not by convenience. Scientific communities such as CHORUS.HIP are built on top of it.

The core idea​

The usual way of working with data is to move it: copy it to a laptop, a shared drive, a departmental server. Every copy is a place it can leak from, and a place nobody is quite accountable for.

CHORUS turns that around. The data stays where it is governed, and everything else travels to it - the analysis tools, the computing power, and the researchers. Because the work happens inside the environment, nothing is downloaded to your own computer while you work.

"Controlled" here is not a vague promise. Four specific things are decided by policy rather than left to individuals:

  • Who gets in - access is granted per person and per project, not shared around.
  • What tools are available - applications come from a reviewed catalogue.
  • What data a project can see - each project's data is confined to that project.
  • What is allowed to leave - results are released through an explicit human decision.

Every consequential action - administrative changes, data movement, opening and closing sessions - is recorded so it can be reviewed afterwards.

What it brings together​

CHORUS combines secure data access, analytical tools, scalable compute, and governance workflows into one system, so that a researcher does not have to assemble them - or negotiate them separately with their institution.

The lifecycle runs in one direction, and each stage has a gate:

  • Data enters through a controlled review, rather than by being uploaded at will.
  • Work happens inside an isolated workspace, using tools launched from a catalogue.
  • Results leave only after an explicit approval decision.
  • Everything is logged along the way.

The unit that holds all this together is the workspace: one project, its data, its people, its tools, its results. Workspaces do not share anything with each other, which is what makes it safe to run projects with very different confidentiality requirements side by side on the same platform.

Communities on CHORUS​

A community is a scientific or institutional grouping of users that lives on the shared platform while keeping its own data, tools, and governance.

CHORUS.HIP - the Human Intracerebral EEG Platform - is the community for intracerebral EEG and neuroimaging research. It is a Trusted Research Environment for that field: the same architecture underneath, with domain-specific datasets, tools, and rules on top.

SPE, TRE - what is the difference?

You will meet both terms, often for the same thing.

A Secure Processing Environment (SPE) is a controlled environment where authorised users work directly with sensitive data, with the tools brought to the data. A Trusted Research Environment (TRE) describes the same essential model, with the emphasis on research use.

The two overlap so heavily that in practice they are used interchangeably. CHORUS describes itself as an SPE, because it is built to host any kind of sensitive data - health, administrative, or research data with confidentiality constraints - not research data alone. A community built on top of CHORUS for a specific research purpose, such as CHORUS.HIP, is a TRE.

Who it is for​

Researchers and clinicians who need to work with sensitive data - often from more than one institution - without moving it out of the environment that governs it.

Institutions that need to offer a secure environment for research on their own data, and want to run it on their own infrastructure under their own rules.

The people who have to sign it off - data protection officers, IT security, ethics committees. Much of this documentation exists for them as much as for the researchers: see Security & governance for how the controls are organised.

Who builds it, and how it is licensed​

CHORUS is developed at Lausanne University Hospital (CHUV) in Switzerland, by the Biomedical Data Science Center together with the Clinical Neurosciences department and the IT department.

The code of the CHORUS platform is source-visible: you can read it, inspect how the security controls actually work, and adapt it under the terms of CHUV's academic non-commercial research licence. Every third-party component CHORUS is built on is open source.

Why "source-visible" and not "open source"

The distinction matters, and it is easy to get wrong.

  • The dependencies CHORUS is assembled from are open source. No proprietary component is bundled into a release.
  • The CHORUS platform layer itself is published under CHUV's academic non-commercial research licence. That licence is not an OSI-approved open-source licence: it does not permit unrestricted redistribution or commercial resale.

What this gives you is inspectability - the ability to verify for yourself how isolation, authentication, controlled import and export, and audit are implemented, rather than taking a vendor's word for it - plus the right for institutions to reuse the platform under the licence terms.

For non-academic or commercial use, a request to CHUV is required. See the CHORUS-TRE organisation on GitHub for the code and the licence text.

Standards and frameworks​

CHORUS is designed to line up with the frameworks institutions are assessed against, rather than inventing its own vocabulary:

  • Five Safes - the reference model for governing access to sensitive data, and the framework CHORUS organises its own security documentation around.
  • SATRE - the reference architecture for Trusted Research Environments.
  • ISO/IEC 27001 - information security management.
  • EU/EHDS and TEHDAS2 - the European Health Data Space regulation and its emerging technical specification for secure processing environments.

Standards covers what each one is and where CHORUS stands against it.

Where to start​

To see how the platform is put together - workspaces, sessions, applications, and who is allowed to do what - read How CHORUS works.

If you are here for intracerebral EEG research, go to CHORUS.HIP.