Privacy Policy
Effective August 9, 2026 · Version 1
This policy covers the GOVENANT standard website (govenantstandard.org) and the hosted GOVENANT Audit service (mcp.govenantstandard.org). GOVENANT is an open standard authored by Scott Fielder and stewarded by iii.partners, the data controller for this service. We audit other people's AI agents for honest, non-theatrical data practices, so ours are stated here in full. Your use of the service is also subject to our Terms of Service.
The one-paragraph version
The GOVENANT Audit reads metrics about the shape and health of your AI agent system — how many agents, how much they deliver, which models they run, whether governance is working — and turns them into a report for you. It never reads your prompts, your agents' inputs or outputs, your customers' data, your database credentials, or your secrets. Your identity (name and provider-verified email) is captured when you sign in, and is used to deliver your report and — only if you consent — to follow up. Aggregated, de-identified findings help improve the open standard. You can export or delete everything we hold about you yourself, any time, from your dashboard.
What we collect
| Category | What | Why |
|---|---|---|
| Identity | Name, provider-verified email, avatar, and (from your email domain) your company and industry, via GitHub, Google, Microsoft, LinkedIn, or GitLab sign-in. | To deliver your report and, with consent, follow up. |
| Audit metrics | Aggregate counts and ratios from your substrate: agent/role count, duty delivery, decision grading, LLM spend totals, conformance level, which model providers you run, and which failure signals fired. | To generate your report and benchmark you. |
| Aggregate research | The above, stripped of identity and coarsened into buckets (e.g. "fintech, 6–20 agents, level 1, 74% delivery"). Cannot be traced back to you. | To evolve the open standard and publish industry benchmarks. |
| Usage & site analytics | Standard web analytics (pages viewed, referrer, coarse region, device type) via PostHog, and product events around using the Audit (e.g. sign-in completed, report generated). | To understand and improve the service. |
| Payments (only if you buy) | Handled by Stripe. We store only Stripe identifiers (customer / charge / subscription IDs) and order metadata — never your card number or bank details. | To process certification, strategy-call, and service payments. |
What we never collect
The line the tool will not cross, by construction:
- Your prompts or system instructions
- Your agents' inputs or outputs (the message payloads)
- Any raw customer records or row-level data from your database
- Database credentials, connection strings, API keys, or secrets
- Your source code or repository contents
We collect how your agents are built and whether they work — never what they process. The audit queries are read-only and aggregate; the fields that could carry customer data do not exist in our schema.
How we use it
- To deliver your report — always.
- To follow up about your results (e.g. a review offer from iii.partners) — only if you opt in, using your identity and the report you chose to share.
- To improve the standard — using the de-identified aggregate data only. Published benchmarks are built from cohorts, never individuals, and small cohorts are suppressed so no single organization can be re-identified.
Legal basis & consent
We process your identity and report to provide the service you requested (contract/legitimate interest). Research use and marketing follow-up are each based on your separate, optional consent, which you grant at sign-in and can withdraw at any time. Consent choices are recorded in an append-only ledger.
Sharing & sub-processors
We do not sell your data. We use a small set of sub-processors to run the service, each receiving only what it needs:
| Sub-processor | Purpose | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, storage | All service data, at rest and in transit |
| OAuth providers (GitHub, Google, Microsoft, LinkedIn, GitLab) | Sign-in & email verification | Your identity, from the provider you choose |
| Stripe | Payments (only if you buy) | Name, email, and payment details — we never see your card |
| iii.partners Agent Hub | Our CRM — follow-up, only with consent | Identity + consented aggregate report metadata (never prompts, rows, repo, or free-text) |
| Cal.com | Scheduling a strategy call | Your name + email to book the time |
| PostHog | Product & site analytics | Usage events, coarse device/region |
One user-controlled exception: if you click "Share this report for a free review," your report and contact go to the iii.partners team for that review. Aggregate research is published only in de-identified, cohort form.
Your controls
Manage all of this yourself in your dashboard → Your data (sign in with the same account you audited with).
- See & export it — download everything we hold about you (identity record, every audit run, report, consent entry, and event) as machine-readable JSON, any time.
- Delete it — one action permanently removes your identity record and every audit run and report we hold; your past contributions to the aggregate research set are already de-identified and unlinkable.
- Revoke consent — email [email protected] to turn off research or marketing use without deleting, or delete outright above; it takes effect going forward.
Retention
Identity and consent records are kept until you ask us to delete them. Identified audit metrics are kept for 24 months, then deleted or coarsened into the anonymous research set. De-identified aggregates are kept indefinitely.
Cookies & analytics
The website uses PostHog for privacy-respecting analytics. The Audit sign-in uses a short-lived, security-only session mechanism during the OAuth flow. We do not use third-party advertising cookies.
Children
The service is intended for developers and organizations and is not directed to anyone under 16.
Changes
We may update this policy; the version and effective date above will change, and material changes to how we use personal data will be surfaced at sign-in.
Contact
Privacy questions, access, or deletion requests: [email protected]. Data steward: iii.partners.