Limitations
What GovIntel does not assess
The capability boundary, restated as a first-class page rather than a footnote, because it is what a buyer most needs to know early.
Currentengine 9.0.0Verified 2026-08-30
| Not assessed | Detail |
|---|---|
| AI governance | No AI system inventory, model registry, or EU AI Act, ISO 42001 or NIST AI RMF logic exists |
| Compliance frameworks | No SOC 2, ISO 27001, NIST CSF, GDPR, PCI DSS or HIPAA control crosswalk exists |
| Cyber insurance | No underwriting or insurability analysis |
| Portfolio or multi-entity | No cross-account or organisation-wide aggregation |
| Continuous monitoring | The assessment is triggered, not continuous |
| Azure, GCP, multi-cloud | AWS only |
| Delivery governance | Collected when a repository is supplied, but not scored |
| Application security | No code analysis, dependency scanning or penetration testing |
| Data governance | No data classification, lineage or residency analysis of your workloads |
| People and process | No policy review, no interviews, no control testing beyond configuration |
Enforced, not merely documented
Two offerings can be delivered. The API refuses to dispatch anything else, and the workflow refuses again before any AWS credential is issued.
An enquiry about something GovIntel has not built is still a conversation, and the form accepts it. It cannot be fulfilled by running an assessment, because the pack that came back would not be the thing that was discussed.
What it does assess
Configuration evidence from one AWS account, scored across security, resilience and cost, against a published methodology. That is a narrower claim than most governance products make.
