Privacy Policy
Effective August 9, 2026 · Version 1
This policy covers the GOVENANT standard website (govenantstandard.org) and the hosted GOVENANT Audit service (mcp.govenantstandard.org). GOVENANT is an open standard authored by Scott Fielder and stewarded by iii.partners, the data controller for this service. We audit other people's AI agents for honest, non-theatrical data practices, so ours are stated here in full.
The one-paragraph version
The GOVENANT Audit reads metrics about the shape and health of your AI agent system — how many agents, how much they deliver, which models they run, whether governance is working — and turns them into a report for you. It never reads your prompts, your agents' inputs or outputs, your customers' data, your database credentials, or your secrets. Your identity (name and provider-verified email) is captured when you sign in, and is used to deliver your report and — only if you consent — to follow up. Aggregated, de-identified findings help improve the open standard. You can see, export, or delete everything at any time.
What we collect
| Category | What | Why |
|---|---|---|
| Identity | Name, provider-verified email, avatar, and (from your email domain) your company and industry, via GitHub, Google, Microsoft, LinkedIn, or GitLab sign-in. | To deliver your report and, with consent, follow up. |
| Audit metrics | Aggregate counts and ratios from your substrate: agent/role count, duty delivery, decision grading, LLM spend totals, conformance level, which model providers you run, and which failure signals fired. | To generate your report and benchmark you. |
| Aggregate research | The above, stripped of identity and coarsened into buckets (e.g. "fintech, 6–20 agents, level 1, 74% delivery"). Cannot be traced back to you. | To evolve the open standard and publish industry benchmarks. |
| Usage & site analytics | Standard web analytics (pages viewed, referrer, coarse region, device type) via PostHog, and product events around using the Audit (e.g. sign-in completed, report generated). | To understand and improve the service. |
What we never collect
The line the tool will not cross, by construction:
- Your prompts or system instructions
- Your agents' inputs or outputs (the message payloads)
- Any raw customer records or row-level data from your database
- Database credentials, connection strings, API keys, or secrets
- Your source code or repository contents
We collect how your agents are built and whether they work — never what they process. The audit queries are read-only and aggregate; the fields that could carry customer data do not exist in our schema.
How we use it
- To deliver your report — always.
- To follow up about your results (e.g. a review offer from iii.partners) — only if you opt in, using your identity and the report you chose to share.
- To improve the standard — using the de-identified aggregate data only. Published benchmarks are built from cohorts, never individuals, and small cohorts are suppressed so no single organization can be re-identified.
Legal basis & consent
We process your identity and report to provide the service you requested (contract/legitimate interest). Research use and marketing follow-up are each based on your separate, optional consent, which you grant at sign-in and can withdraw at any time. Consent choices are recorded in an append-only ledger.
Sharing
We do not sell your data or share it with third parties. The single exception is entirely in your hands: if you click "Share this report for a free review," your report and contact are sent to the iii.partners team for that review. We use privacy-respecting sub-processors to run the service (Cloudflare for hosting and storage; PostHog for analytics). Aggregate research is published only in de-identified, cohort form.
Your controls
- See it — request everything we hold about you.
- Export it — machine-readable, on request.
- Delete it — we remove your lead record and purge your personal data; your past contributions to the aggregate research set are already de-identified and unlinkable.
- Revoke consent — turn off research or marketing use at any time; it takes effect going forward.
Retention
Identity and consent records are kept until you ask us to delete them. Identified audit metrics are kept for 24 months, then deleted or coarsened into the anonymous research set. De-identified aggregates are kept indefinitely.
Cookies & analytics
The website uses PostHog for privacy-respecting analytics. The Audit sign-in uses a short-lived, security-only session mechanism during the OAuth flow. We do not use third-party advertising cookies.
Children
The service is intended for developers and organizations and is not directed to anyone under 16.
Changes
We may update this policy; the version and effective date above will change, and material changes to how we use personal data will be surfaced at sign-in.
Contact
Privacy questions, access, or deletion requests: [email protected]. Data steward: iii.partners.