FAQ
Frequently asked questions
The questions asked most often before an engagement, answered against what the product actually does rather than what would sell best.
What exactly do we receive?
A dated, versioned board pack PDF, delivered through your own GovIntel portal. It covers your governance posture, the material risks a board should understand, every failed control, what the evidence covered, and the recommended actions.
An Evidence Register is produced with every successful assessment, listing every failed control with the resources it was observed on. It is available on request.
Is this a replacement for a SOC 2 audit?
No, and it does not claim to be. A SOC 2 audit is a formal process conducted by a certified auditor against defined criteria. This is a governance assessment of your AWS environment. The two answer different questions.
Does GovIntel modify infrastructure or deploy agents?
No agent, and nothing you already run is modified. Access is strictly read-only. You grant it with a single CloudFormation stack that creates one IAM role, and, if your account does not already have one, the identity provider that role trusts. Those are the only resources it creates.
How does the access work, and when does it end?
The role is assumed through GitHub OIDC: a short-lived token minted for one repository and one branch, with no stored credential. The role carries an expiry date set when you deploy it, enforced by its own trust policy, so access stops working on that date whether or not anyone remembers to remove it.
Delete the stack at any time to revoke it sooner.
Can GovIntel read our data?
No. Object contents, database records, log events, secrets, parameters and function code are denied outright by explicit deny statements, which override every permission including those from the AWS managed policies. See What is explicitly denied.
What happens if the assessment cannot read enough of our environment?
You are told, plainly, rather than given a rating the evidence does not support. The pack states what was examined and what could not be reached, and if coverage is too thin to support a conclusion a board could rely on, GovIntel says so.
Do you compare us against our industry?
No. No board pack contains a peer comparison, because no peer dataset with a stated methodology exists. See Peer benchmarking.
Is the exposure figure what a breach would cost us?
No. It is an indicative magnitude derived from the count and severity of failed controls. It is not actuarial, uses no external loss data, contains no likelihood term, and is not a prediction of loss to your organisation.
How long do we keep access to the board pack?
Packs are retained for a limited period, and the portal shows the date yours remains available until. Download a copy and keep it with your board records.
How long does it take?
GovIntel publishes no turnaround figure, because it has not measured enough engagements to stand behind one. See Timing.
Can we assess more than one AWS account?
One account per engagement. There is no organisation-wide scan or portfolio rollup.
Can we verify any of this ourselves?
Yes, and it is encouraged. See Verification.
