Security

Privacy-First Research Platform

We take the security and privacy of your research data seriously. PosterVault is built on secure, industry-standard cloud infrastructure — we use Amazon Web Services (AWS) for encrypted data storage and Cloudflare for secure content delivery and access protection. We support FAIR data principles and incorporate privacy safeguards aligned with the requirements of PIPEDA, GDPR, and CCPA. No advertising. No user data sales. No third-party analytics SDKs.

Multi-layer data encryption

TLS 1.2+ for all data in transit. All research posters and files are stored in encrypted cloud storage (AES-256 encryption at rest). Access is controlled through authenticated sessions and role-based permissions, and downloads are delivered via signed, short-lived URLs.

No data sharing

Six sub-processors. Zero ad networks. Zero analytics SDKs. We do not sell or share personal data, ever.

AI that respects your research

Optional AI features analyze poster content to generate tags, summaries, and insights limited to the archived content. No research data is used to train public AI models.

Implemented today

What's protecting your data right now

Where your data lives
  • Poster files — Amazon Web Services (AWS) encrypted object storage, private access only
  • Cloudflare — secure content delivery, WAF and access protection in front of the platform
  • PostgreSQL — managed cluster on private networking, TLS required for every connection
  • Files are workspace-isolated and served via signed, short-lived URLs
Authentication
  • Email + password with scrypt hashing — plaintext is never stored
  • Google OAuth via NextAuth v5 (Auth.js)
  • JWT sessions with short expiry; refresh on activity
  • Password reset & invite tokens are hashed and expire (60 min / 7 days)
Access control
  • Lab-scoped permissions — every API route checks ownership or membership
  • Role-based access: Owner, Admin, Member, Viewer
  • Submission links are single-purpose: upload only, expiry + max-uses, revocable
  • Comments are off by default; PI toggles them per subfolder
Audit & abuse defence
  • AI usage events recorded per lab — token spend, model, scope, cost
  • Rate limiting on authentication and form endpoints
  • Server-side validation of every upload (MIME + size limit)
  • Failed-login & token-use telemetry retained for investigation
What we don't collect
  • No Google Analytics, Mixpanel, Segment, or advertising SDKs
  • No third-party tracking pixels in marketing or app
  • No card data on our servers — Stripe handles every payment field
  • No model training on your content — OpenAI API doesn't train by default
Sub-processors (only six)
  • Amazon Web Services (AWS) — encrypted file storage
  • Cloudflare — content delivery + security (WAF)
  • DigitalOcean — managed database hosting
  • OpenAI — AI summaries; API content is not used for training
  • SendGrid — transactional email only
  • Stripe — subscriptions; we never see card numbers
Standards

Compliance posture

FrameworkStatusWhat it means for you
PIPEDA (Canada)alignedProcessing aligned with the ten fair-information principles for personal data.
GDPR / UK GDPRrights honoredAccess, rectification, erasure, portability, restriction, objection — see Privacy Policy §9.
CCPA / CPRArights honoredKnow, delete, correct, opt-out of sale (we don't sell), limit sensitive-PI use.
SOC 2 (infrastructure)inheritedAWS, Cloudflare and DigitalOcean are SOC 2 Type II certified — our hosting layer inherits those controls.
ISO 27001 (infrastructure)inheritedAWS, Cloudflare and DigitalOcean hold ISO 27001 certification for the managed services we use.
SOC 2 Type II (PosterVault)targetedAudit firm engagement under evaluation. Expected reporting in 2027.
HIPAA / BAAnot applicablePosterVault is not intended for PHI. Do not upload patient-identifiable health data.
FERPAcontractually addressableDPA available for US institutions handling student educational records.

Our infrastructure aligns with commonly used security frameworks in academic and enterprise environments. “Inherited” means the underlying infrastructure provider carries the certification and we operate within its controls. “Targeted” means we are actively working toward attestation.

On the roadmap

What's coming next

Next quarter
  • Self-serve data export — download everything in your lab as a single archive
  • Self-serve account deletion with 30-day soft-delete window
  • Two-factor authentication (TOTP)
  • In-app audit log for lab owners
Institution tier
  • SSO / SAML (Okta, Azure AD, Shibboleth)
  • Customer-managed encryption keys (BYOK)
  • IP allow-listing for admin operations
  • Auto-generated Data Processing Agreement on demand
  • Annual third-party penetration testing report
  • SOC 2 Type II report under NDA

Questions about security or compliance?

For DPA requests, penetration-test summaries, sub-processor lists, or institutional procurement, reach our security team directly.

Disclosed a vulnerability? Email security with “Vulnerability Report” in the subject. We commit to acknowledging within 2 business days.