Digital collaboration
- The Teams structure of the project environment
- Central data repository via SharePoint integration
- Digital platforms for electronic lab notebooks (ELN)
- Identification, guest access and identity security
- Data sovereignty and ownership documentation during upload
- Responsibility of team owners (gatekeeper principle)
- App governance, lifecycle and IT resilience
- Web meetings and virtual communication via Teams
The Teams structure of the project
- The general channel: Used for daily coordination and the exchange of information with a low confidentiality level (according to TLP). It is available to all members of a team and forms the basis for joint exchange.
- Structured specialist channels: Specific channels (e.g. for individual work packages in EU consortia or exchange with project auditors) separate communication by topic and minimise information loss. They are usually accessible to a strictly defined, restricted group of users within the environment and allow targeted information provision according to the need-to-know principle.
- External data channel (partner input): We set up dedicated channels or storage areas for the secure receipt of information provided to us by third parties. Data in these areas (the partners’ ‘background IP’) is strictly separated from our own research data, clearly marked as external data and only stored for a limited period of time before being securely deleted or archived in accordance with specifications.
With this standardised and cloud-based architecture, acib GmbH ensures that all research and project data – from agile internal coordination to strictly regulated collaboration with international consortium partners and auditors – is managed securely, traceably and in compliance with regulations at all times. The consistent use of the Microsoft 365 ecosystem in conjunction with clearly defined information flows thus not only forms the technological foundation for our networked cutting-edge research in industrial biotechnology. It also guarantees maximum protection of our own intellectual property and the trustworthy and legally compliant handling of our partners’ sensitive data.
Central data repository via SharePoint integration
Behind every Microsoft Team is a dedicated, secure SharePoint instance that acts as our central data repository for the respective project or work area. This seamless integration ensures highly secure and structured data storage in the background:
- Single source of truth (central storage): We actively avoid decentralised storage and data silos. All relevant documents, research reports and raw data are managed and edited exclusively in the SharePoint structure of the associated team.
- Seamless versioning and audit trail: The architecture of SharePoint enables automated and seamless version control. Every change to a document is historically traceable. This is an essential component of our quality assurance and a basic requirement for fulfilling the strict documentation obligations towards national and international funding bodies (e.g. FFG, European Commission).
- Granular access control: Through restrictive, role-based rights management at the SharePoint folder and Teams channel level, we ensure that sensitive research data is strictly protected according to the need-to-know principle. Only explicitly authorised project members are granted access to the information relevant to them.
- Consistent TLP labelling: We use the Traffic Light Protocol (TLP) for visual and technical classification of confidentiality. All channels and the documents shared in them are labelled according to their sensitivity. This provides immediate clarity for all internal and external participants as to how the information provided may be handled and whether it may be passed on. Verweis auf TLP
- DLP and retention policies: We use data loss prevention (DLP) and automated retention policies to actively control the lifecycle of data and prevent data leakage. This is particularly relevant for external data (background IP from partners): this is labelled accordingly and, after a defined period or at the end of the project, is automatically blocked, archived or securely deleted in order to fully comply with our contractual deletion obligations (data lifecycle management).
Digital platforms for electronic lab notebooks (ELN)
Microsoft OneNote for agile basic documentation
- Good Scientific Practice (GWP): The use of OneNote complies with our internal GWP guidelines. All entries are linked to metadata (time stamp and unique creator) by the M365 integration, which supports basic traceability in accordance with the ALCOA+ standard.
- Central availability: Since laboratory records often form the preliminary stage for subsequent patent applications, central storage in the cloud ecosystem (SharePoint backend) prevents local data loss and ensures that the team has access to the current state of research at all times.
eLabJournal for regulated and audit-proof environments
- Complete audit compliance: eLabJournal offers unalterable audit trails and electronic signatures in accordance with industry standards (e.g. 21 CFR Part 11).
- Strict compliance: Every change is cryptographically secured and logged, enabling the system to serve as legally valid evidence in regulatory audits, strict quality controls or complex patent disputes.
Identification, guest access and identity security
- Individual identification: Access is granted exclusively on the basis of a personal, individually assignable email address. Clear identification of the natural person behind this address is a mandatory requirement for collaboration.
- Exclusion of functional addresses: The use of role-based collective or functional addresses (e.g. office@…, info@…) is prohibited. This is the only way we can ensure complete traceability (audit trail) of every action and every file access.
- Liability for email security: Each guest is fully responsible for the security of their own email account. The guest is liable for any damage resulting from the compromise of their own account and any resulting unauthorised access to acib systems.
- Invitation process & deadlines: Invitations for guest access expire automatically if they are not accepted within 30 days. After that, a new invitation must be requested from the responsible team owner.
- Access via one-time passcodes (OTC) & terms of use: Partners do not necessarily need a Microsoft account. Access is granted via secure one-time passcodes (OTC), which are sent to the verified email address each time the user logs in. Before accessing the system for the first time, guests must explicitly agree to the acib terms of use. If the email address is already linked to a Microsoft account, this will be used for seamless sign-on (SSO).
- Tenant switching: Partners must actively switch to the acib tenant in their Teams app to access the shared workspaces. For selected, long-term strategic collaborations, we reserve the right to use shared channels (Teams Connect) to avoid this switch.
- Lifecycle management and automatic blocking: If a person leaves the partner company, their guest access authorisation is immediately revoked. In addition, automated lifecycle management takes effect: if a guest does not log into the acib tenant for more than 70 days, access is automatically deactivated, unless different project deadlines have been specified.
- Right to immediate blocking: acib GmbH expressly reserves the right to revoke guest access at any time and without prior notice if there are doubts about identity, suspicion of misuse or if the purpose of the cooperation ends prematurely.
Terms of use and code of conduct for guests in the acib tenant
In order to ensure security and compliance within our digital project environment, guest access is subject to strict General Terms and Conditions of Use (GTCU) that must be accepted upon registration. These regulate technical and behavioural obligations and apply in addition to existing project and confidentiality agreements (e.g. NDAs, consortium agreements).
- Purpose limitation and prohibition of private use: The platform and all data provided may only be used for the agreed business or scientific purposes within the scope of the respective cooperation.
- Strict prohibition of local storage: The permanent local storage of platform data on the guest’s private or company-owned end devices is prohibited. Downloads are only permitted for the absolutely necessary processing time and must then be irrevocably deleted.
- Shadow IT and data leakage: Guests are strictly prohibited from forwarding or copying confidential acib data to unauthorised external cloud services (e.g. private Dropbox, Google Drive) or private email accounts.
- Use of artificial intelligence (AI): The feeding of project or research data into public, free AI tools (e.g. ChatGPT Free, DeepL Free) is strictly prohibited due to uncontrolled data leakage (‘model training’). The use of AI is only permitted with dedicated enterprise solutions that are certified or have ‘zero data retention’ policies to guarantee that no input data is used for training.
- Recording ban (meetings): The recording of video or audio conferences (including the use of AI-supported protocol aids) is strictly prohibited without the express prior consent of all participants.
- Obligation to report security incidents: In the event of suspected data theft, compromised access data, confiscation of devices or discontinuation of the purpose of cooperation (e.g. change of job by the guest), acib GmbH must be informed immediately at security@acib.at <security@acib.at> in order to arrange for immediate blocking of access.</security@acib.at>
Special data rooms (password-protected shares)
- Provision via SharePoint: Password-protected shares (‘EVERYONE links’ with mandatory password protection) are created via SharePoint.
- Strict short-term nature: These shares are intended exclusively for temporary data exchange (e.g. if the effort involved in onboarding for a one-time file transfer would be disproportionate). They are always assigned a short, defined expiry date by the system.
- Password security and prohibition of disclosure: The assigned password is communicated to the recipient via a separate communication channel (out-of-band, e.g. SMS or telephone). Disclosure of the password to third parties is strictly prohibited and constitutes a serious security breach
However, the binding standard for regular, ongoing project work remains authenticated guest access without restriction.
Data sovereignty and ownership documentation during upload
- Strict separation through folder structures: Partners upload their own prior knowledge and research data (‘background IP’) exclusively to isolated folders explicitly designated for this purpose (e.g., labelled ‘Partner Input’). This structural separation ensures that ownership of the know-how contributed can be clearly distinguished at all times from the results generated jointly or by acib (‘foreground IP’).
- Prohibition of decentralised distribution: Partner data must be uploaded to the dedicated SharePoint/Teams areas. The unstructured sending of background IP via email attachments or personal chat messages is prohibited, as this results in a loss of central control and tagging.
- Metadata labelling: As soon as external data is uploaded to the designated areas, acib GmbH labels it (partly automatically) with the appropriate metadata. This includes, in particular, confidentiality labels (e.g. TLP AMBER+STRICT), which technically prevent unauthorised forwarding.
- Automated deletion and retention periods: External data submitted is subject to strict lifecycle rules. The system assigns an expiry date to it. At the end of the defined project term or a contractually agreed period, automated deletion policies (retention policies) take effect, irrevocably removing the partner data from the systems of acib GmbH. This ensures that we comply with our contractual return or destruction obligations completely and verifiably.
Responsibility of team owners (gatekeeper principle)
- Internal responsibility (staffing): Team owners are, without exception, permanent employees of acib GmbH. The transfer of owner rights to external guests or partners is prohibited by the system.
- Fail-safe (redundancy): In order to ensure administrative continuity during holidays, sick leave or staff changes, acib GmbH strives to have at least two owners for each active team.
- Audit checks (access reviews): Owners are obliged to carry out regular checks (access reviews) of the member lists. Authorisations must be adjusted or revoked immediately in the event of personnel changes (e.g. departure of a project partner) in order to minimise the risk of orphaned accesses.
- Information flow control: The owner is responsible for ensuring that the defined channel structure (e.g. separation of general channel and partner input) is adhered to and that TLP labelling is correctly applied to confidential documents.
App governance, lifecycle and IT resilience
- App whitelisting (governance): Only applications that have been tested and explicitly approved by acib IT (whitelisting) may be installed and used within Microsoft Teams. This prevents security gaps caused by untested third-party software (shadow IT) within the tenant.
- Archiving and data loss prevention (DLP): The integrity of our research data is protected by Microsoft Purview Data Loss Prevention (DLP), which actively prevents unauthorised data leakage. After project completion, automated lifecycle rules also come into effect, archiving project data in an audit-proof and unalterable manner, usually for 10 years (or in accordance with the specifications of the funding bodies).
- Redundant backup strategy: In addition to Microsoft’s native redundancy, all critical research and project data (especially from SharePoint and OneNote) is backed up using an independent, external backup solution (e.g. in cooperation with regional partners such as ACP). This guarantees maximum reliability in the event of ransomware attacks or critical system failures.
Web meetings and virtual communication via Teams
- Confidentiality in meetings (lobby function): For external meetings or meetings with sensitive content, the ‘waiting area’ function (lobby) in Teams must be activated. The organiser (host) checks the identity of the participants before granting them access to the virtual room. Uncontrolled access by anonymous users must be prevented.
- Telephone dial-in (audio conferencing): Dial-in to Teams meetings via a traditional telephone (PSTN) is permitted in order to ensure flexibility in the event of technical problems or for external partners. However, as telephone participants cannot be strongly authenticated by the system, the lobby principle must be applied here. The host must verify the identity of the caller (based on the number and after admission by voice) before discussing confidential content. If the identity is doubtful, participation is unfortunately not possible. For mobile participation in Teams meetings, the use of mobile Teams clients is recommended.
- Physical environment and confidentiality (clean desk/eavesdropping): Participation in meetings with confidential content (TLP AMBER or higher) must take place in locations where listening or reading by unauthorised third parties (eavesdropping/shoulder surfing) is impossible. The use of headsets is required in open-plan offices or in home offices (in the presence of third parties). Likewise, a neutral background (virtual background or blur effect) must be ensured so as not to reveal any unintended information from the working environment.
- Strict prohibition of recording: The recording of audio or video conferences is strictly prohibited. Recording may only take place in justified exceptional cases and requires the prior, express and documented consent of all participants present.
- Secure presentation sharing (PowerPoint): Special care must be taken to prevent confidential speaker notes or hidden slides from being shared unintentionally.
Sharing should be done either via the integrated ‘PowerPoint Live’ function in Teams (which securely separates the view) or via targeted window sharing and use of the presentation mode in the window (sharing of the single window only, not the entire desktop or presentation mode). - Screen sharing with caution: In general, the need-to-know principle should be observed when sharing content. Ensure that no sensitive background information (e.g. open email inboxes, chat messages or pop-up desktop notifications) is visible to third parties. Only specific application windows should be shared, never the entire desktop.
- AI-supported protocol aids (Microsoft Copilot): The use of integrated AI tools such as Microsoft Copilot for automated transcription or summarisation of meetings is permitted, as these fall under the Enterprise DLP guidelines of acib GmbH (zero data retention). However, their use must be transparently announced by the host at the beginning of the meeting. External, unapproved AI note-taking bots (e.g. Otter.ai) are not permitted in meetings.
Preferred use and alternative systems
Expressly excluded tools and shadow IT
- External AI note-taking bots (e.g. Otter.ai, Read.ai): These automated note-takers upload voice recordings and transcripts to external servers without control, posing a massive threat to IP protection and confidentiality. The host must remove such bots from the meeting.
- Consumer communication services (e.g. WhatsApp, private Skype accounts): These do not offer sufficient enterprise security standards and are not subject to centralised access control (MFA/SSO).
- Unauthorised collaboration clouds (e.g. free Miro or Mural boards): The integrated Microsoft Whiteboard should primarily be used for visual brainstorming. Free third-party tools without an official data processing agreement (DPA) and enterprise licensing lead to uncontrollable leakage of project IP and are therefore classified as shadow IT.