Overview
What GovIntel does not do
The exclusions are enforced in configuration rather than merely documented: no AI governance, no framework mapping, no monitoring, AWS only.
This page exists because the fastest way to lose a board's trust is to imply a capability that does not exist. Everything below is enforced in configuration, not just written down.
Not built
| Not provided | Detail |
|---|---|
| AI governance assessment | There is no AI system inventory, model registry, or EU AI Act, ISO 42001 or NIST AI RMF logic anywhere in the product |
| Compliance framework mapping | No SOC 2, ISO 27001, NIST CSF, GDPR, PCI DSS or HIPAA control crosswalk exists |
| Cyber insurance analysis | No underwriting or insurability assessment |
| Portfolio aggregation | No multi-entity or cross-account rollup |
| Continuous monitoring | The assessment is triggered, not continuous |
| Azure, GCP, multi-cloud | AWS only |
Peer benchmarking
A benchmark comparison is emitted only when a peer dataset with stated provenance, methodology and sample size is configured. None ships, so no board pack currently carries a peer comparison. That is the correct default until a dataset with a defensible methodology exists.
How the exclusions are enforced
Two offerings can be delivered by the assessment backend. Any other request is captured as a conversation and never dispatched, because dispatching it would run the AWS assessment and return a pack that is not the thing that was discussed.
The refusal happens twice — once in the API and once again in the workflow, before any AWS credential is issued.
