PRINCETON ANALYTICA

Security

Built for confidential corporate research

Your questions, uploads and reports are sensitive. The platform is designed as a multi-tenant system handling confidential information from the first line of infrastructure code.

Encryption

Data is encrypted at rest with customer-managed encryption keys and in transit with TLS 1.2+. Report PDFs are never public objects.

Tenant isolation

Every diagnostic, quote, order, report, file and download is scoped to your account and authorized server-side. Identifiers are non-enumerable; changing an ID in a URL cannot reach another customer's report.

Controlled delivery

Reports are delivered through your dashboard with short-lived signed links tied to your session — not as email attachments.

Payments

A PCI DSS-compliant payment processor handles card details. We store order metadata only — never card numbers. Report generation begins only after server-side, signature-verified payment confirmation.

Untrusted content

Web pages and uploaded documents are treated as data, not instructions. Content that attempts to manipulate the research process is ignored and flagged as low quality. Automated guardrails screen prompt attacks and harmful content.

Authentication

Email verification, strong password policy, optional multi-factor authentication, token revocation and password reset.

Edge protection

Web application firewall with rate limiting and managed rule sets, edge TLS termination, strict security headers and API throttling.

Logging and monitoring

Centralized audit logs, metrics and alarms, structured job tracing and failure alerts to our operations team. Secrets are held in a managed vault, never in code.

Retention and deletion

Raw uploads expire automatically (default 90 days), intermediate research artifacts expire after 180 days, and your reports remain in your library until you delete them. You can request full deletion at any time.

Least privilege

Each pipeline stage runs with an IAM role scoped to the resources it needs. Infrastructure is defined as code and reviewed before change.

Transparency

Where we are honest about limits

Our controls are described in detail in the Data Processing & Security document, including our subprocessor categories and our incident-response commitment. Our infrastructure and payment providers maintain independent SOC 2 and PCI DSS certifications.

Reports are produced with AI systems under human-designed controls. We label facts, derived calculations, estimates and forecasts; we maintain a registered source list; and we fact-check before delivery. Models can still err — see the AI-Assisted Research Disclosure and report any error to support@princetonanalytica.com.

Responsible disclosure: security researchers can reach us at security@princetonanalytica.com.

Ready to turn a question into a decision?

Describe what you need to understand. The diagnostic scopes the research and quotes a fixed price in minutes.