On April 28, 2026, Carnegie Mellon University, Huron, Kharon, and Digital Science came together for a webinar called “Building a Research Security Program.” The session looked at how institutions can move beyond reactive, manual compliance checks and toward a proactive, data-driven approach to research security, in a landscape shaped by federal mandates like NSPM-33 and international frameworks such as Canada’s STRAC.

The panel covered a lot of ground, from how to read the current regulatory pressure, to what a modern review workflow looks like in practice, to how a research security officer decides where to focus first. One of the clearest illustrations came early on, when Heidi Becker, Product Manager for Dimensions Research Security at Digital Science, used a real, public settlement to show what a data-driven review can catch. It is one example among several from the session, but it is a useful place to start, and it sets up the data layer that the rest of the discussion built on.

A real settlement, and what could have caught it

Becker opened her portion of the session with a press release from the United States Department of Justice dated December 16, 2024: “University of Delaware Failed to Disclose Professor’s Foreign Government Ties.” The settlement related to a NASA grant issued to UD in June 2020. Since 2011, federal law has prohibited NASA from using funds to collaborate with China or Chinese-owned companies. The University of Delaware paid $700,000 to resolve allegations that it failed to disclose significant connections to China on the part of the principal investigator. The investigator’s ties included: employment at a Chinese university, participation in a program established by the Chinese government to recruit individuals with knowledge of or access to foreign technology and intellectual property, and a grant from the National Natural Science Foundation of China.

Becker used this case to show what could have been caught before it became a $700,000 problem for the University.

Risk can surface before you have a name attached to it

Becker was clear about the approach: “We’re not profiling people. We’re looking at data related to their research activities.” In the Dimensions product, she searched for researchers in engineering at the University of Delaware who acknowledged NASA funding and also published with an affiliation in China. That search surfaced a researcher with multiple affiliations on record, publications tied to a home organization, and a “recent affiliations timeline” showing overlapping activity at a Chinese university and the University of Delaware across the entire span of the researcher’s employment. As Becker put it, even without the researcher’s name, the platform could surface the case by looking at foreign affiliations.

The takeaway: build review criteria around research behavior, not just names on a watchlist. Looking at who is publishing where, and with which funders, can surface a concern before you ever need to identify an individual.

Full text search catches what disclosure forms miss

The settlement listed three specific disclosure failures. Dimensions was able to surface each one directly:

  • For the Chinese university employment, the data showed the affiliation timeline overlapping with the researcher’s entire tenure at Delaware.
  • For the talent-recruitment program, Becker noted that “we have full text access to publications in Dimensions because of our relationships with academic publishers,” which let the team search funding and acknowledgment sections for keywords tied to talent recruitment programs. That search identified four publications where the funding was mentioned and the researcher was listed as a co-author.
  • For the grant from the National Natural Science Foundation of China, Dimensions had already indexed three awarded grants from that funder to the same researcher.

Becker’s conclusion was direct: “All of this information was available, could have and should have been disclosed, potentially saving the University of Delaware $700,000 in settlement fees.”

The takeaway: disclosure verification should not stop at what a researcher chooses to report. Cross-referencing publications, acknowledgments, grants, and funder data can confirm or contradict a disclosure using records that already exist.

A clean sanctions screen is not the finish line

Ethan Woolley, Global Director of Strategy at Kharon, picked up where Becker left off, using the Kharon platform to map the Chinese university named in the settlement, Xiamen University. His starting point was a reminder that matters for every research security program: “They’re not a sanctioned university. They’re not on an entity list currently.”

That is exactly the gap Kharon’s data is built to close. Woolley showed that Xiamen University’s School of Aerospace Engineering has a documented partnership with a Chinese company called Beijing Lingkong Tianxing Technology Co., Ltd., a hypersonic aerospace and missile manufacturer. According to Beijing Lingkong Tiangxing’s own website, Xiamen University was described as a “cooperative partner” (translated from Chinese). The two organizations share five joint patents on rocket design and control, and a 2023 Xiamen University press release described a joint rocket research course involving more than 20 students in rocket development and launch at a Xinjiang test site. Woolley added that Beijing Lingkong is not on a sanctions list either, but holds military and government licenses for classified research, and supplies listed defense firms including Norinco and China Aerospace Science and Technology Corporation, plus a partnership with Harbin Institute of Technology, both on the BIS entity list.

The takeaway: a clean sanctions screen does not mean a clean risk profile. Institutional and corporate relationships, patents, joint programs, and even a company’s own marketing language can reveal exposure that a restricted party list will never show.

How the Dimensions and Kharon partnership works

Dimensions and Kharon are both built on transparent, source-backed data. Together, they surface restricted-entity connections and complementary risk signals in a single workflow, helping joint customers see the complete risk picture and make faster, more confident decisions. Kharon’s research security solution is built to look past standard watchlist screening and expose the kind of obscured relationships Woolley demonstrated: ownership structures, joint ventures with state-linked entities, and hidden relationships with military end users. Kharon states directly that its data and insights extend beyond watchlists to uncover affiliations of concern tied to foreign universities, research institutes, and companies. For research institutions specifically, Kharon’s risk intelligence integrates with Digital Science’s Dimensions Research Security platform, embedding that intelligence directly into research management systems. 

In practice, this joint solution means a research security team does not have to choose between publication and funding data on one side and entity-relationship intelligence on the other. Dimensions identifies  the researcher-level signals: affiliations, funding, publications, grants, and patents. Kharon supplies the deeper network context: who an entity is connected to, what those connections mean, and whether they carry military, state-ownership, or export control risk. Woolley described the workflow at the end of his demonstration: Kharon processes a list of entities for which it has identified risk, Dimensions Research Security both surfaces that list and lets a user jump directly into Kharon’s ClearView platform to do a deeper dive via platform-to-platform links.

Learn more

The example above is just one look at how Dimensions Research Security and Kharon’s data work together to surface risks that manual checks tend to miss. If you want to see how the product itself handles disclosure verification, affiliation review, and funding checks, you can learn more about Dimensions Research Security.

For a closer look at how an institution puts this into practice, join the upcoming webinar “Research security in practice: Building a connected due diligence workflow” on September 16.