Security
Built for confidential corporate research
Your questions, uploads and reports are sensitive. The platform is designed as a multi-tenant system handling confidential information from the first line of infrastructure code.
Encryption
Data is encrypted at rest with AWS KMS customer-managed keys (DynamoDB, S3) and in transit with TLS 1.2+. Report PDFs are never public objects.
Tenant isolation
Every diagnostic, quote, order, report, file and download is scoped to your account and authorized server-side. Identifiers are non-enumerable; changing an ID in a URL cannot reach another customer's report.
Controlled delivery
Reports are delivered through your dashboard with short-lived signed links tied to your session — not as email attachments.
Payments
Stripe Checkout handles card details under PCI DSS. We store order metadata only — never card numbers. Report generation begins only after server-side, signature-verified payment confirmation.
Untrusted content
Web pages and uploaded documents are treated as data, not instructions. Content that attempts to manipulate the research process is ignored and flagged as low quality. Bedrock Guardrails screen prompt attacks and harmful content.
Authentication
Amazon Cognito with email verification, strong password policy, optional multi-factor authentication, token revocation and password reset.
Edge protection
AWS WAF with rate limiting and managed rule sets, CloudFront TLS termination, strict security headers and API throttling.
Logging and monitoring
CloudTrail, CloudWatch logs, metrics and alarms, structured job tracing and failure alerts to our operations team. Secrets live in AWS Secrets Manager.
Retention and deletion
Raw uploads expire automatically (default 90 days), intermediate research artifacts expire after 180 days, and your reports remain in your library until you delete them. You can request full deletion at any time.
Least privilege
Each pipeline stage runs with an IAM role scoped to the resources it needs. Infrastructure is defined as code and reviewed before change.
Transparency
Where we are honest about limits
Princeton Analytica does not yet hold a SOC 2 report. Our controls are described in detail in the Data Processing & Security document, including our subprocessors (Amazon Web Services and Stripe) and our incident-response commitment.
Reports are produced with AI systems under human-designed controls. We label facts, derived calculations, estimates and forecasts; we maintain a registered source list; and we fact-check before delivery. Models can still err — see the AI-Assisted Research Disclosure and report any error to support@princetonanalytica.com.
Responsible disclosure: security researchers can reach us at security@princetonanalytica.com.
Ready to turn a question into a decision?
Describe what you need to understand. The diagnostic scopes the research and quotes a fixed price in minutes.