← Trust Directory

GitHub

github.com · 1 assessment

GitHub
Security review required
1 blocking issue to resolve before signing
Assessed Aug 31, 2026 · public evidence coverage 30% · evidence confidence medium high · methodology 0.7.0
Not scored — insufficient public evidenceFull report →

Assessed before company and product grades were shown separately; see the product assessments below.

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

GitHub Copilot
Security review required
1 blocking issue to resolve before signing
Assessed Aug 31, 2026 · public evidence coverage 30% · evidence confidence medium high · methodology 0.7.0
Not scored — insufficient public evidenceFull report →

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
EU-U.S. Data Privacy Framework
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 31, 2026

CSA STAR Level 2
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 31, 2026

FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 31, 2026

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Aug 31, 2026.