Security & Privacy

Reporting a vulnerability

How to report a security issue in GovIntel, what to include, and what GovIntel does and does not commit to in response.

Currentengine 9.0.0Verified 2026-08-30

How to report

Write to the contact address published on the GovIntel website and on the Privacy Policy. It reaches the company rather than an operations mailbox.

What to include

  • What you found, and where
  • How to reproduce it
  • What an attacker could do with it
  • Anything you did while establishing it

What GovIntel commits to

Reading it, taking it seriously, and telling you what was done.

What GovIntel does not commit to

No response-time commitment, no service level and no bounty. GovIntel is a small company and nothing in the product measures the interval between a report and a reply, so a stated turnaround would be a promise nobody could keep on purpose or notice breaking.

Saying so is more useful than publishing a figure that is not backed by anything.

Please do not

  • Access, modify or exfiltrate data belonging to another customer
  • Degrade the service for others
  • Test against a customer's AWS account. The access boundary is the thing worth testing, and it is fully readable from a template rather than by probing a live engagement

Reviewing the access boundary instead

The strongest security review of GovIntel does not require permission or a live target. The role, its grants, its denials and its trust conditions are all deployed into your own account, where you can read them. See Verify the access boundary.

Known gaps GovIntel publishes about itself

GovIntel's own engineering documentation records open security gaps in its internal console rather than presenting the system as complete. Those are internal surfaces behind authentication and are not part of the customer-facing product, but their existence is acknowledged rather than denied.