Privacy-First Research Platform
We take the security and privacy of your research data seriously. PosterVault is built on secure, industry-standard cloud infrastructure — we use Amazon Web Services (AWS) for encrypted data storage and Cloudflare for secure content delivery and access protection. We support FAIR data principles and incorporate privacy safeguards aligned with the requirements of PIPEDA, GDPR, and CCPA. No advertising. No user data sales. No third-party analytics SDKs.
Multi-layer data encryption
TLS 1.2+ for all data in transit. All research posters and files are stored in encrypted cloud storage (AES-256 encryption at rest). Access is controlled through authenticated sessions and role-based permissions, and downloads are delivered via signed, short-lived URLs.
No data sharing
Six sub-processors. Zero ad networks. Zero analytics SDKs. We do not sell or share personal data, ever.
AI that respects your research
Optional AI features analyze poster content to generate tags, summaries, and insights limited to the archived content. No research data is used to train public AI models.
What's protecting your data right now
- Poster files — Amazon Web Services (AWS) encrypted object storage, private access only
- Cloudflare — secure content delivery, WAF and access protection in front of the platform
- PostgreSQL — managed cluster on private networking, TLS required for every connection
- Files are workspace-isolated and served via signed, short-lived URLs
- Email + password with scrypt hashing — plaintext is never stored
- Google OAuth via NextAuth v5 (Auth.js)
- JWT sessions with short expiry; refresh on activity
- Password reset & invite tokens are hashed and expire (60 min / 7 days)
- Lab-scoped permissions — every API route checks ownership or membership
- Role-based access: Owner, Admin, Member, Viewer
- Submission links are single-purpose: upload only, expiry + max-uses, revocable
- Comments are off by default; PI toggles them per subfolder
- AI usage events recorded per lab — token spend, model, scope, cost
- Rate limiting on authentication and form endpoints
- Server-side validation of every upload (MIME + size limit)
- Failed-login & token-use telemetry retained for investigation
- No Google Analytics, Mixpanel, Segment, or advertising SDKs
- No third-party tracking pixels in marketing or app
- No card data on our servers — Stripe handles every payment field
- No model training on your content — OpenAI API doesn't train by default
- Amazon Web Services (AWS) — encrypted file storage
- Cloudflare — content delivery + security (WAF)
- DigitalOcean — managed database hosting
- OpenAI — AI summaries; API content is not used for training
- SendGrid — transactional email only
- Stripe — subscriptions; we never see card numbers
Compliance posture
| Framework | Status | What it means for you |
|---|---|---|
| PIPEDA (Canada) | aligned | Processing aligned with the ten fair-information principles for personal data. |
| GDPR / UK GDPR | rights honored | Access, rectification, erasure, portability, restriction, objection — see Privacy Policy §9. |
| CCPA / CPRA | rights honored | Know, delete, correct, opt-out of sale (we don't sell), limit sensitive-PI use. |
| SOC 2 (infrastructure) | inherited | AWS, Cloudflare and DigitalOcean are SOC 2 Type II certified — our hosting layer inherits those controls. |
| ISO 27001 (infrastructure) | inherited | AWS, Cloudflare and DigitalOcean hold ISO 27001 certification for the managed services we use. |
| SOC 2 Type II (PosterVault) | targeted | Audit firm engagement under evaluation. Expected reporting in 2027. |
| HIPAA / BAA | not applicable | PosterVault is not intended for PHI. Do not upload patient-identifiable health data. |
| FERPA | contractually addressable | DPA available for US institutions handling student educational records. |
Our infrastructure aligns with commonly used security frameworks in academic and enterprise environments. “Inherited” means the underlying infrastructure provider carries the certification and we operate within its controls. “Targeted” means we are actively working toward attestation.
What's coming next
- Self-serve data export — download everything in your lab as a single archive
- Self-serve account deletion with 30-day soft-delete window
- Two-factor authentication (TOTP)
- In-app audit log for lab owners
- SSO / SAML (Okta, Azure AD, Shibboleth)
- Customer-managed encryption keys (BYOK)
- IP allow-listing for admin operations
- Auto-generated Data Processing Agreement on demand
- Annual third-party penetration testing report
- SOC 2 Type II report under NDA
Questions about security or compliance?
For DPA requests, penetration-test summaries, sub-processor lists, or institutional procurement, reach our security team directly.
Disclosed a vulnerability? Email security with “Vulnerability Report” in the subject. We commit to acknowledging within 2 business days.