Privacy Policy

Effective August 9, 2026 · Version 1

This policy covers the GOVENANT standard website (govenantstandard.org) and the hosted GOVENANT Audit service (mcp.govenantstandard.org). GOVENANT is an open standard authored by Scott Fielder and stewarded by iii.partners, the data controller for this service. We audit other people's AI agents for honest, non-theatrical data practices, so ours are stated here in full. Your use of the service is also subject to our Terms of Service.

The one-paragraph version

The GOVENANT Audit reads metrics about the shape and health of your AI agent system — how many agents, how much they deliver, which models they run, whether governance is working — and turns them into a report for you. It never reads your prompts, your agents' inputs or outputs, your customers' data, your database credentials, or your secrets. Your identity (name and provider-verified email) is captured when you sign in, and is used to deliver your report and — only if you consent — to follow up. Aggregated, de-identified findings help improve the open standard. You can export or delete everything we hold about you yourself, any time, from your dashboard.

What we collect

CategoryWhatWhy
Identity Name, provider-verified email, avatar, and (from your email domain) your company and industry, via GitHub, Google, Microsoft, LinkedIn, or GitLab sign-in. To deliver your report and, with consent, follow up.
Audit metrics Aggregate counts and ratios from your substrate: agent/role count, duty delivery, decision grading, LLM spend totals, conformance level, which model providers you run, and which failure signals fired. To generate your report and benchmark you.
Aggregate research The above, stripped of identity and coarsened into buckets (e.g. "fintech, 6–20 agents, level 1, 74% delivery"). Cannot be traced back to you. To evolve the open standard and publish industry benchmarks.
Usage & site analytics Standard web analytics (pages viewed, referrer, coarse region, device type) via PostHog, and product events around using the Audit (e.g. sign-in completed, report generated). To understand and improve the service.
Payments (only if you buy) Handled by Stripe. We store only Stripe identifiers (customer / charge / subscription IDs) and order metadata — never your card number or bank details. To process certification, strategy-call, and service payments.

What we never collect

The line the tool will not cross, by construction:

We collect how your agents are built and whether they work — never what they process. The audit queries are read-only and aggregate; the fields that could carry customer data do not exist in our schema.

How we use it

Legal basis & consent

We process your identity and report to provide the service you requested (contract/legitimate interest). Research use and marketing follow-up are each based on your separate, optional consent, which you grant at sign-in and can withdraw at any time. Consent choices are recorded in an append-only ledger.

Sharing & sub-processors

We do not sell your data. We use a small set of sub-processors to run the service, each receiving only what it needs:

Sub-processorPurposeWhat it receives
CloudflareHosting, database, storageAll service data, at rest and in transit
OAuth providers (GitHub, Google, Microsoft, LinkedIn, GitLab)Sign-in & email verificationYour identity, from the provider you choose
StripePayments (only if you buy)Name, email, and payment details — we never see your card
iii.partners Agent HubOur CRM — follow-up, only with consentIdentity + consented aggregate report metadata (never prompts, rows, repo, or free-text)
Cal.comScheduling a strategy callYour name + email to book the time
PostHogProduct & site analyticsUsage events, coarse device/region

One user-controlled exception: if you click "Share this report for a free review," your report and contact go to the iii.partners team for that review. Aggregate research is published only in de-identified, cohort form.

Your controls

Manage all of this yourself in your dashboard → Your data (sign in with the same account you audited with).

Retention

Identity and consent records are kept until you ask us to delete them. Identified audit metrics are kept for 24 months, then deleted or coarsened into the anonymous research set. De-identified aggregates are kept indefinitely.

Cookies & analytics

The website uses PostHog for privacy-respecting analytics. The Audit sign-in uses a short-lived, security-only session mechanism during the OAuth flow. We do not use third-party advertising cookies.

Children

The service is intended for developers and organizations and is not directed to anyone under 16.

Changes

We may update this policy; the version and effective date above will change, and material changes to how we use personal data will be surfaced at sign-in.

Contact

Privacy questions, access, or deletion requests: [email protected]. Data steward: iii.partners.