Verification
Reviewer checklist
A single-page checklist for a security reviewer, auditor or evaluator assessing whether GovIntel is what it says it is.
Currentengine 9.0.0Verified 2026-08-30
Everything below is checkable from information you already hold.
Access
- The deployed role's principal is a federated web identity, not a user or an account
- The trust policy pins both the audience and the subject
- The subject names one repository and one branch
- Session names are constrained to a
govintel-prefix - No new session may be issued after the engagement expiry
- A separate deny statement blocks every action after that expiry
- Maximum session duration is one hour
- Inline grants contain no create, modify, delete or invoke action
- A deny policy blocks object and record content, secrets, parameters, cryptographic operations, log and stream content, code and image retrieval, and role assumption
- Deleting the stack removes the access
Execution
- CloudTrail shows one federated assume-role event per assessment
- CloudTrail shows configuration reads only, and no write of any kind
- No activity appears after the engagement expiry
- The evidence ledger's collector states reconcile with the trail
Methodology
- The pack prints the thresholds, weights, severity weights and materiality rules applied
- The scanner and its version are named
- The severity scope is stated, and low severities are absent
- The control population is stated and is within a plausible range
- Excluded and ignored counts are stated
Scoring
- Domain scores recompute from the printed constants
- The overall is withheld, not re-based, where a domain is unscored
- The overall band is not better than the security band
- Ceilings were applied to the band and not to the score
- Population minimums were respected
- Confidence is measured over scored domains, not collectors
Disclosure
- Exposure carries its full basis and non-actuarial statement
- Cost recovery is excluded from exposure
- No peer benchmark appears unless a dataset with stated provenance is configured
- Unclassified controls are reported as unclassified, with coverage published
- Not re-assessed appears as a distinct state from closed
Known limits, stated by GovIntel
- Individual control results are not independently audited
- Resilience coverage is close to zero for a predominantly serverless estate
- Three families of check are disabled by the read-only boundary
- The comparison window is bounded by artifact retention
