Verification

Reviewer checklist

A single-page checklist for a security reviewer, auditor or evaluator assessing whether GovIntel is what it says it is.

Currentengine 9.0.0Verified 2026-08-30

Everything below is checkable from information you already hold.

Access

  • The deployed role's principal is a federated web identity, not a user or an account
  • The trust policy pins both the audience and the subject
  • The subject names one repository and one branch
  • Session names are constrained to a govintel- prefix
  • No new session may be issued after the engagement expiry
  • A separate deny statement blocks every action after that expiry
  • Maximum session duration is one hour
  • Inline grants contain no create, modify, delete or invoke action
  • A deny policy blocks object and record content, secrets, parameters, cryptographic operations, log and stream content, code and image retrieval, and role assumption
  • Deleting the stack removes the access

Execution

  • CloudTrail shows one federated assume-role event per assessment
  • CloudTrail shows configuration reads only, and no write of any kind
  • No activity appears after the engagement expiry
  • The evidence ledger's collector states reconcile with the trail

Methodology

  • The pack prints the thresholds, weights, severity weights and materiality rules applied
  • The scanner and its version are named
  • The severity scope is stated, and low severities are absent
  • The control population is stated and is within a plausible range
  • Excluded and ignored counts are stated

Scoring

  • Domain scores recompute from the printed constants
  • The overall is withheld, not re-based, where a domain is unscored
  • The overall band is not better than the security band
  • Ceilings were applied to the band and not to the score
  • Population minimums were respected
  • Confidence is measured over scored domains, not collectors

Disclosure

  • Exposure carries its full basis and non-actuarial statement
  • Cost recovery is excluded from exposure
  • No peer benchmark appears unless a dataset with stated provenance is configured
  • Unclassified controls are reported as unclassified, with coverage published
  • Not re-assessed appears as a distinct state from closed

Known limits, stated by GovIntel

  • Individual control results are not independently audited
  • Resilience coverage is close to zero for a predominantly serverless estate
  • Three families of check are disabled by the read-only boundary
  • The comparison window is bounded by artifact retention