Security & Privacy
What GovIntel holds
The categories of data GovIntel actually stores about you and your environment, and why each one is needed to run the engagement.
Currentengine 9.0.0Verified 2026-08-30
| Category | What it is | Why |
|---|---|---|
| Enquiry details | Your name, work email, company, and what you asked about | To reply to you and to run the engagement |
| Engagement record | Offering, cloud environment, region scope, and the status of the work | To run the assessment |
| AWS account identifier | Your 12-digit account number | So the role identifier can be derived rather than transcribed by you |
| Role identifier | The identifier of the role you created | It grants nothing on its own |
| Onboarding audit trail | When links were issued and used, and the addresses they were used from | So the authentication of a customer session is auditable |
| Assessment results | The board pack, and the derived Evidence Register, which is available on request | The deliverable |
| Assessment snapshot | A fingerprinted record of the previous result | So the next assessment can state what changed |
| Provenance | Engine version, scanner version, severity scope, regions, confidence | So a delivered pack can be reconstructed |
What is derived rather than collected
The assessment results are derived from configuration evidence read from your account. That evidence is retained for a short period and is not part of what GovIntel keeps long-term.
The snapshot holds no identifiers
Control identifiers are the scanner's, resource identity is carried as fingerprints, and the account identifier is fingerprinted too. It names no resource and no account.
The role identifier is not a credential
It names a role. It confers nothing without a token that satisfies the role's own trust conditions, which GovIntel can only obtain from one workflow in one repository on one branch.
