Data Processing & Security
Effective 2026-08-21 · Version 2026-08-21
This page describes the technical and organizational measures Princeton Analytica uses to protect customer data. It is provided for transparency and does not modify or expand any warranty or obligation set out in our Terms of Service.
1. 1. Infrastructure
The Service runs on Amazon Web Services (AWS) infrastructure, primarily in the us-east-1 (Northern Virginia) region. We rely on AWS's managed services for compute, storage, authentication, and networking rather than operating our own data centers.
2. 2. Encryption
Data at rest, including uploaded files, intermediate research artifacts, and generated reports, is encrypted using AWS Key Management Service (KMS)-managed encryption keys. Data in transit is encrypted using TLS 1.2 or higher for all connections to our website, dashboard, and APIs.
3. 3. Storage and Access to Files
Uploaded files and generated reports are stored in private storage that is not publicly accessible. Downloads are served through short-lived, signed URLs that expire after a limited time, rather than permanent public links.
4. 4. Tenant Isolation and Authorization
Customer data is logically isolated by account, and access to any customer's data is enforced through server-side authorization checks tied to that customer's authenticated session. Internal systems follow the principle of least-privilege access: employees and automated services are granted only the access needed to perform their function.
5. 5. Logging and Monitoring
We use AWS CloudTrail and Amazon CloudWatch to log administrative and system activity and to monitor for anomalous behavior across our infrastructure, supporting incident detection and after-the-fact investigation.
6. 6. Network Protections
Our web application is protected by a web application firewall (WAF) and rate limiting designed to mitigate common web attacks and abusive automated traffic.
7. 7. Payment Data
All payment card data is collected and processed directly by Stripe, a payment processor that maintains its own PCI DSS (Payment Card Industry Data Security Standard) compliance. We do not store full card numbers, CVV codes, or other sensitive card data on our own systems.
8. 8. Authentication
Customer accounts are authenticated through Amazon Cognito using email and password credentials, with optional multi-factor authentication (MFA) available for additional account security. We encourage customers to enable MFA where available.
9. 9. Data Retention and Deletion
Raw customer uploads are retained by default for 90 days and then automatically deleted. Intermediate research artifacts generated during report production are retained by default for 180 days and then automatically deleted. Generated reports remain available in your account library until you request deletion. Customers may request earlier deletion of their data by contacting privacy@princetonanalytica.com.
10. 10. Subprocessors
We rely on the following categories of subprocessors to provide the Service. We may update this list as our vendor relationships evolve.
- Amazon Web Services (AWS) — hosting, storage, compute, authentication (Cognito), and AI processing (Amazon Bedrock)
- Stripe — payment processing
11. 11. Incident Response
We maintain internal procedures to investigate and respond to suspected security incidents affecting customer data. If we determine that a security incident has resulted in unauthorized access to your personal information, we will notify affected customers and relevant authorities as required by applicable law.
12. 12. Responsible Disclosure
If you believe you have discovered a security vulnerability affecting our Service, please report it to security@princetonanalytica.com. We ask that you give us a reasonable opportunity to investigate and address any reported issue before disclosing it publicly, and that you do not access or modify data that is not your own in the course of your research.
13. 13. Compliance Status
Princeton Analytica has not yet completed a SOC 2 or similar third-party compliance audit. We rely on the security capabilities of our underlying infrastructure providers (including AWS and Stripe, which maintain their own compliance certifications) together with the practices described on this page. We will update this page if and when our own compliance certifications change.