PRINCETON ANALYTICADecision-grade intelligence

Security

Built for confidential corporate research

Your questions, uploads and reports are sensitive. The platform is designed as a multi-tenant system handling confidential information from the first line of infrastructure code.

Encryption

Data is encrypted at rest with AWS KMS customer-managed keys (DynamoDB, S3) and in transit with TLS 1.2+. Report PDFs are never public objects.

Tenant isolation

Every diagnostic, quote, order, report, file and download is scoped to your account and authorized server-side. Identifiers are non-enumerable; changing an ID in a URL cannot reach another customer's report.

Controlled delivery

Reports are delivered through your dashboard with short-lived signed links tied to your session — not as email attachments.

Payments

Stripe Checkout handles card details under PCI DSS. We store order metadata only — never card numbers. Report generation begins only after server-side, signature-verified payment confirmation.

Untrusted content

Web pages and uploaded documents are treated as data, not instructions. Content that attempts to manipulate the research process is ignored and flagged as low quality. Bedrock Guardrails screen prompt attacks and harmful content.

Authentication

Amazon Cognito with email verification, strong password policy, optional multi-factor authentication, token revocation and password reset.

Edge protection

AWS WAF with rate limiting and managed rule sets, CloudFront TLS termination, strict security headers and API throttling.

Logging and monitoring

CloudTrail, CloudWatch logs, metrics and alarms, structured job tracing and failure alerts to our operations team. Secrets live in AWS Secrets Manager.

Retention and deletion

Raw uploads expire automatically (default 90 days), intermediate research artifacts expire after 180 days, and your reports remain in your library until you delete them. You can request full deletion at any time.

Least privilege

Each pipeline stage runs with an IAM role scoped to the resources it needs. Infrastructure is defined as code and reviewed before change.

Transparency

Where we are honest about limits

Princeton Analytica does not yet hold a SOC 2 report. Our controls are described in detail in the Data Processing & Security document, including our subprocessors (Amazon Web Services and Stripe) and our incident-response commitment.

Reports are produced with AI systems under human-designed controls. We label facts, derived calculations, estimates and forecasts; we maintain a registered source list; and we fact-check before delivery. Models can still err — see the AI-Assisted Research Disclosure and report any error to support@princetonanalytica.com.

Responsible disclosure: security researchers can reach us at security@princetonanalytica.com.

Ready to turn a question into a decision?

Describe what you need to understand. The diagnostic scopes the research and quotes a fixed price in minutes.