Confidential and sensitive data

EPCC offers two distinct sets of services to store and process sensitive and confidential data: EPCC Safe Haven Services and EIDF Confidential Data Workspace. EIDF provides many services to store and process non-sensitive and non-confidential data, including EIDF Virtual Desktops. In the table below we compare the features of three services.

EPCC offers two distinct sets of services to store and process sensitive and confidential data: 

  • EPCC Safe Haven Services
  • EIDF Confidential Data Workspace

EIDF provides many services to store and process non-sensitive and non-confidential data, including EIDF Virtual Desktops. 

In the table below we compare the features of three services. 

Feature

EPCC Safe Haven Services

EIDF Confidential Data Workspace

EIDF Virtual Desktop

Accreditation

Yes

Yes

Yes

Yes

No

No

Yes

No

No

Yes

Yes

Yes

Assistance with 3rd- party penetration testing

Yes

No

No

Data and usage policies & agreements

Storage of unconsented identifiable special-category PII

Yes

No

No

Storage of de-identified or consented PII

Yes

Yes

No

Agreements and policies

TRE Service Agreement (available upon request)

Project leads and managers has sudo (super/admin user) access on virtual machines

No

Yes

Yes

Project lead and managers can transfer data in and out of virtual desktops

No

Yes

Yes

Project users can transfer data in and out of their virtual desktop

No

No

Yes

EPCC support

Helpdesk tickets to resolve issues that require EPCC staff to login to the virtual machines or interact with project data (e.g., upgrade software in a VM to newer version, copy data into storage)

Yes

No

No

Helpdesk tickets to resolve issues that do not require EIDF staff to login to the virtual machines (e.g., not able to login to a desktop)

Yes

Yes

Yes

Setup and bootup the virtual infrastructure

Yes

Yes

No

Data wrangling (ingress, clean, filter, transform, egress) or analysis (train/test models, quality-check, disclosure tests)

No4

No4

No4

Dedicated service manager for the project

Yes

No

No

Infrastructure cost

20TB storage included

Yes

No2

No2

1/3 server included

Yes

No1

No1

Electricity cost

Equal share of entire SHS cost

Included in cost of each infrastructure component

Included in cost of each infrastructure component

Staff costs

Equal share of entire SHS cost + cost to cover share of helpdesk ticket load

Included in cost of each infrastructure component

Included in cost of each infrastructure component

Project leads and managers can switch on/off use of virtual services

No

Yes

Yes

Backups and disaster recovery

Infrastructure disaster recovery included to different media

No6

No6

No6

14-days rolling backups on same media

Yes

No

No

Additional compute resources

Safe Haven GPU Cluster

Yes1

No

No

Safe Haven CPU Cluster

Yes1

No

No

EIDF GPU Service

No

In development1

Yes 1

EIDF Cirrus (CPU)

No

No

Yes 1

Target costs (not price!)

Approx guidance on cost per annum

£200,000 3

£30,000 3

£15,000 3 

1 Billed in units per hour depending on the type of virtual machine (#cores, #GPUs, #memory, #VM-storage) and GPU/CPUs, e.g., GPU-hours reserved on the SHS GPU Cluster. 

2 Billed in TB-hours per month where price depends on type of storage used, VAT, commercial or academic.

3 Prices depend both on the type of customer (internal or external to university, grant collaborator or not, commercial or public sector) and the type and amount of resources the customer requires. Here we provide typical costs. Our pricing is based on staff costs, electricity, licenses, capital depreciation, overheads, estates, VAT, etc.

4 Data wrangling, data analyses and software/infrastructure engineering tasks can be performed by EPCC staff and are separately agreed and costed in a contract.

5 Users are responsible for managing the access to the Confidential Data Workspace VMs including Router management. The EIDF team are not responsible for any unauthorised or unexpected access to VMs including ingress or egress of data or network traffic. The EIDF team will not be able to assist with any issues arising from unauthorised access to VMs or data sharing.

6 Disaster recovery copies can be arranged and will be costed in addition.