Risk & Scoring
What the scores do not mean
The limits of every number in the pack, stated in one place, so nothing in it is read as a claim the assessment cannot support.
The scores are not a certification
No auditor is engaged, no opinion is issued, and nothing GovIntel produces attests compliance with any framework. A green band is not a certificate and must not be presented as one.
They model nothing about your business
Not revenue. Not data value. Not workload criticality. Not customer impact. Not regulatory position. Not the probability of compromise.
The assessment observes none of those, and the scoring contains no term for any of them.
Materiality is reach, not consequence
A band of estate-wide says a failure touches a large part of the account. It says nothing about what that would cost you if exploited.
The exposure range is not a loss estimate
Not actuarial, not derived from external loss data, contains no likelihood term, and is not a prediction of loss to your organisation. See The exposure range.
A score is bounded by what was observable
A domain rated over the minimum population is still a domain rated over what the collectors could reach. The coverage limits are published, per domain, and they are real. See Coverage limits, domain by domain.
An unrated domain is not a passing domain
Not assessed means not assessed. It is not a quiet pass and not a zero.
The score has not been independently audited
The pipeline has been validated end to end against a real AWS account. What has not been done is an independent audit of whether each individual control result is correct about the account it describes. See What GovIntel validates about itself.
What the scores do mean
That a defined set of controls, over a stated scope, at a stated time, produced a stated result under a published methodology you can recompute. That is a narrower claim than most governance products make, and it is one that survives inspection.
