AWS Public Sector Blog
The NBDC sandbox: How the Masonic Institute for the Developing Brain built a secure cloud environment to accelerate brain development research with AWS

The Adolescent Brain Cognitive Development (ABCD) and HEALthy Brain and Child Development (HBCD) studies, the largest longitudinal brain development studies in U.S. history, are producing transformative insights, but the data driving those discoveries require greater security and have grown so large that many research teams struggle to access and analyze them.
Researchers working with large-scale brain development data have long followed a familiar workflow of downloading the data, storing it locally, and analyzing it through institutional systems. But new National Institutes of Health (NIH) security requirements and rapidly expanding volumes have made that process unsustainable for many teams. “The data has become almost impossible to handle if you’re not an informaticist or don’t have one on speed dial,” said Dr. Damien Fair, co-director of the Masonic Institute for the Developing Brain (MIDB) at the University of Minnesota (UMN).
Dr. Fair, MIDB, and Lasso Informatics designed and developed the NIH Brain Development Cohorts (NBDC) Sandbox as a secure environment for accessing and analyzing sensitive data. With support from Amazon Web Services (AWS) and AWS Partner ScaleCapacity, the NBDC Sandbox was implemented on the AWS Cloud in a secure, scalable fashion, empowering users to access ABCD and HBCD data in place, with no downloads required.
Why the data demands new workflows
For the past decade, the ABCD Study has tracked about 12,000 participants from age nine or 10 through young adulthood. The newer HBCD Study extends that model, starting in the second trimester of pregnancy and following subjects up to the point where the ABCD Study begins. Both studies investigate how experiences, histories, biology, and exposures influence brain development.
Researchers working with data from these studies face two tough challenges. The first is the data’s size and scope. These high-dimensional datasets contain billions of elements across a wide range of data types, including MRI, EEG, behavioral, biosensor, bio samples, and genetic data. Their volume and complexity far exceed what most institutions can download and store locally.
The second is stringent security standards. New NIH mandates, introduced in January 2025, significantly expand compliance requirements to strengthen privacy and data protection. Strict policies substantially limit access, and required data-use certifications constrain collaboration by prohibiting data sharing outside secure systems. “That is an issue because most universities and laboratories don’t have those types of environments,” said Dr. Fair.
While the MIDB team had constructed an on-premises environment for the NBDC, these NIH mandates challenged the team to think beyond this environment and consider new approaches that allow for more flexible expansion to meet new community needs. They needed a cloud-based, compliant companion that was built for how researchers work, with familiar tools, scalable resources, and predictable costs. To construct it quickly and effectively, they needed support.
Shaping a solution with AWS
MIDB had recently built a HIPAA-secure AWS environment for a Department of Defense (DoD) telehealth project at UMN, so working with AWS again was the natural next step.
AWS helped Dr. Fair and Lasso plan the execution and identify ScaleCapacity as the right collaborator to implement a hybrid framework within the UMN environment.
Creating a compliant research environment in under a year required the full cross-functional team. “It was an all-hands-on-deck effort to put this environment in play,” Dr. Fair explained.
How the NBDC Sandbox works
Researchers access the Sandbox via the centralized, user-friendly NBDC Data Hub and use familiar tools such as Jupyter notebooks, RStudio, Python, and Linux. Because Amazon Simple Storage Service (Amazon S3) stores and mounts the data directly in the file system, research teams bypass the download step entirely.
The environment uses AWS ParallelCluster with Slurm for high-performance computing (HPC), supporting both batch and interactive workloads. The cluster elastically scales compute resources, including GPUs, based on demand. Separate Slurm queues offer different tiers of resources, so researchers can select the right level of compute for their workload, from lightweight data exploration to intensive neuroimaging analysis. Fair-share scheduling distributes these resources equitably, and when the system reaches capacity, additional jobs are queued rather than incurring unexpected costs or halting work mid-process.
The environment also includes pre-installed neuroimaging tools—FreeSurfer, FSL, AFNI, and Connectome Workbench—so researchers can run MRI and diffusion tensor imaging (DTI) analysis, cortical surface reconstruction, brain segmentation, and other processing tasks without configuring software.
The Sandbox’s architecture mirrors that of most university supercomputing centers, so researchers skip the learning curve. It also keeps costs fixed and predictable. For academic teams operating within tight grant budgets, this feature is crucial. “They don’t want to see quadruple the cost they budgeted, or to see their work stop because resources have run out,” said Dr. Fair. “So, having that kind of functionality is really important.”
Open OnDemand serves as the intuitive user-facing layer on top of AWS ParallelCluster. Through a browser-based interface, researchers can launch and monitor jobs, manage files, and run tools like Jupyter and RStudio, all without deep HPC knowledge or local setup. A hybrid model combines local and cloud-based resources to keep costs down. In total, this technical design offers cost-predictability and a frictionless user experience.
Expanding access across the research community
The NBDC Sandbox is changing how researchers work with large-scale data on brain development. “It reduces barriers to science,” explained Dr. Fair. “The real-world impact is, hopefully, accelerating new discoveries.” Across the research community, the benefits will be concrete:
- Institutions no longer need to build and maintain compliant on-premises environments to access the data.
- Cross-institutional teams will be able to share data within a secure environment, supporting collaboration that was previously difficult.
- Researchers can work in familiar environments without needing to set up new systems or learn new workflows.
- Institutions without dedicated informatics teams can access and use high-dimensional datasets.
- Researchers can spend less time on the technical aspects of data access and more time on the science.
Early results reveal growing demand
The NBDC Sandbox went live in November 2025, and the initial response has been positive: “People are just happy that they have it,” said Dr. Fair.
Researchers are using the environment for training sessions, hackathons, and workshops, including at the annual HBCD meeting. It also supports programs such as the Scientific Training in Addiction Research Techniques (START) program, which helps scholars at institutions with limited computing resources work with these datasets.
Usage trends underscore the expanding need for cloud-based compute environments. “Demand is only increasing as more people learn about it,” said Dr. Fair. “It’s definitely growing quite a bit.” The team expects it to increase further as file-based data just became available at the end of April 2026.
Building a blueprint for the research community
Dr. Fair and the Lasso team envision a future in which researchers access brain development data exclusively through cloud-based environments.
To advance that vision, they constructed a repeatable, cloud-first model for accessing sensitive data. MIDB’s environment serves as a blueprint for institutions to reference when developing their own implementations, which can now be deployed from Lasso as a Secure Analytics Framework Environment (SAFE) or Lasso SAFE.
Dr. Fair, MIDB, and the Lasso team are still refining the NBDC Sandbox. They plan to explore evolving tools and technologies that expand support for institutional teamwork through collaborative spaces and derived data sharing (or community collections). They are also the model in which institutions can secure their own SAFE environment that meets institutional needs and NIST compliance requirements, while continuing to optimize the user experience.
Bringing the compute to the data
Expanding data volumes and tightening NIH security mandates are accelerating a shift toward cloud-based research computing. The NBDC Sandbox demonstrates that with familiar tools, predictable costs, and accessible systems, the benefits of making that shift extend well beyond compliance.
MIDB’s implementation of SAFE (NBDC Sandbox) provides institutions with a replicable roadmap for executing an increasingly urgent transformation. “This movement is coming,” Dr. Fair said. “The question is, are you prepared for it?”
When your team is ready to bring the compute to the data, AWS can assist. Learn how AWS helps research institutions securely access, analyze, and collaborate on large-scale datasets in the cloud.