Security & Privacy

What GovIntel holds

The categories of data GovIntel actually stores about you and your environment, and why each one is needed to run the engagement.

Currentengine 9.0.0Verified 2026-08-30

CategoryWhat it isWhy
Enquiry detailsYour name, work email, company, and what you asked aboutTo reply to you and to run the engagement
Engagement recordOffering, cloud environment, region scope, and the status of the workTo run the assessment
AWS account identifierYour 12-digit account numberSo the role identifier can be derived rather than transcribed by you
Role identifierThe identifier of the role you createdIt grants nothing on its own
Onboarding audit trailWhen links were issued and used, and the addresses they were used fromSo the authentication of a customer session is auditable
Assessment resultsThe board pack, and the derived Evidence Register, which is available on requestThe deliverable
Assessment snapshotA fingerprinted record of the previous resultSo the next assessment can state what changed
ProvenanceEngine version, scanner version, severity scope, regions, confidenceSo a delivered pack can be reconstructed

What is derived rather than collected

The assessment results are derived from configuration evidence read from your account. That evidence is retained for a short period and is not part of what GovIntel keeps long-term.

The snapshot holds no identifiers

Control identifiers are the scanner's, resource identity is carried as fingerprints, and the account identifier is fingerprinted too. It names no resource and no account.

The role identifier is not a credential

It names a role. It confers nothing without a token that satisfies the role's own trust conditions, which GovIntel can only obtain from one workflow in one repository on one branch.