GitHub Copilot

github.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
58 / 100C
Procurement decision
Security review required
3 conditions outstanding
  • Training on customer data splits sharply by tier and by GitHub's role
  • No clear commitment that your data will not train their models
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Training on customer data splits sharply by tier and by GitHub's roleBlocking

Why it matters: Three documents point in different directions for different scopes. (1) Copilot Individual and Free under the Terms of Service (effective 27 April 2026): Inputs and Outputs are licensed to GitHub and its Affiliates for model training by default, with a prospective account-settings opt-out; private repository content supplied as Input falls under the same rule; GitHub will not pass Inputs or Outputs to third-party model providers for their own training, but Affiliates such as Microsoft may use them. (2) Copilot Business and Enterprise under the (deprecated) Product Specific Terms: prompts are used for no purpose other than generating suggestions, and the Terms of Service expressly carve Customer Agreement and volume-licence customers out of the J.3 training licence. (3) The General Privacy Statement, which applies only where GitHub is data controller, says Personal Data including code, inputs and AI outputs is used to train models and may be shared with Microsoft for the same purpose; for organization-provided accounts GitHub is processor under the DPA, so this language does not describe Business or Enterprise customer content. Separately, Section D.4 of the Terms of Service licenses all hosted Your Content for training AI Features and Affiliates' models, outside the J.3 opt-out.

What to ask for: For our plan (Copilot Business or Enterprise) and purchase channel, confirm in writing under the GitHub Generative AI Services Terms that prompts, code context, repository content and suggestions are not used to train or fine-tune any GitHub, Microsoft or third-party model, and whether any Copilot telemetry or feedback data is excluded from that commitment.

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We use your Inputs to generate Outputs and provide the AI Features. You also grant GitHub and its Affiliates a license to collect and use your Inputs and Outputs to develop, train and improve artificial intelligence and machine learning models and technologies including those that power AI Features, unless (a) you opt out through your account settings, or (b) your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Unless you opt out, GitHub's Affiliates may use your Inputs and Outputs under this license in accordance with their applicable privacy and contractual obligations. This license does not, however, permit GitHub or its Affiliates to share your Inputs or Outputs with third-party AI model providers for their own independent model training purposes.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“The training and data-use provisions in Section J.3 apply only to individual licenses. If your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement, those agreements govern the use of your data in connection with AI Features and Section J.3 does not apply to you.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“If you provide your private repository content as Input to AI Features, we may use that Input to provide, develop, train, and improve the Service, including AI Features. Your ability to opt out under Section J.3 applies to this use of private repository content. We will not otherwise use your private repository contents to develop or improve the Service.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“You grant GitHub and our Affiliates the right to store, host, archive, parse, display, and make copies of Your Content as necessary to provide, develop, and improve the Service, including by training AI Features, and for the purpose of training, developing, and improving artificial intelligence and machine learning models and technologies of our Affiliates.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements.”
No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We use your Inputs to generate Outputs and provide the AI Features. You also grant GitHub and its Affiliates a license to collect and use your Inputs and Outputs to develop, train and improve artificial intelligence and machine learning models and technologies including those that power AI Features, unless (a) you opt out through your account settings, or (b) your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“If you provide your private repository content as Input to AI Features, we may use that Input to provide, develop, train, and improve the Service, including AI Features. Your ability to opt out under Section J.3 applies to this use of private repository content. We will not otherwise use your private repository contents to develop or improve the Service.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“You grant GitHub and our Affiliates the right to store, host, archive, parse, display, and make copies of Your Content as necessary to provide, develop, and improve the Service, including by training AI Features, and for the purpose of training, developing, and improving artificial intelligence and machine learning models and technologies of our Affiliates.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.”
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“A. Generally. GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“CLI and Other Tools. If you use GitHub Copilot tools that operate outside of your code editor, such as Copilot for the Command Line Interface, GitHub Copilot retains your Prompts to those tools to provide the service. Private Language Models. If you have requested a customized private language model, GitHub Copilot retains your Prompts to fine-tune your private model. Custom Settings. If you have configured GitHub Copilot to use alternative data handling, such as enabling interaction with third party extensions, GitHub Copilot will retain your Prompts based on that configuration.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“We’ll retain your Personal Data as long as your account is active and as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements. The retention duration depends on the purpose of data collection and any legal obligations.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

Under the Terms of Service effective 27 April 2026, individual-licence users grant GitHub and its Affiliates a licence to collect and use their Inputs and Outputs (prompts, workspace code, conversation history, suggestions) to develop, train and improve AI models. Training is on by default and stops only prospectively from an account-settings opt-out, or where a Customer Agreement or volume licensing agreement governs.

Requires written confirmation — see Before you sign ↓

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We use your Inputs to generate Outputs and provide the AI Features. You also grant GitHub and its Affiliates a license to collect and use your Inputs and Outputs to develop, train and improve artificial intelligence and machine learning models and technologies including those that power AI Features, unless (a) you opt out through your account settings, or (b) your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“If you provide your private repository content as Input to AI Features, we may use that Input to provide, develop, train, and improve the Service, including AI Features. Your ability to opt out under Section J.3 applies to this use of private repository content. We will not otherwise use your private repository contents to develop or improve the Service.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“You grant GitHub and our Affiliates the right to store, host, archive, parse, display, and make copies of Your Content as necessary to provide, develop, and improve the Service, including by training AI Features, and for the purpose of training, developing, and improving artificial intelligence and machine learning models and technologies of our Affiliates.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.”
!How long do they keep your data?Ask the vendor

Under the October 2024 Product Specific Terms, Copilot Business and Enterprise prompts are encrypted in transit, used only to generate suggestions in real time, deleted once suggestions are generated, and not stored at rest without the customer's permission. The document states it is deprecated for subscriptions and renewals from 5 March 2026.

Requires written confirmation — see Before you sign ↓

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“A. Generally. GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“CLI and Other Tools. If you use GitHub Copilot tools that operate outside of your code editor, such as Copilot for the Command Line Interface, GitHub Copilot retains your Prompts to those tools to provide the service. Private Language Models. If you have requested a customized private language model, GitHub Copilot retains your Prompts to fine-tune your private model. Custom Settings. If you have configured GitHub Copilot to use alternative data handling, such as enabling interaction with third party extensions, GitHub Copilot will retain your Prompts based on that configuration.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“We’ll retain your Personal Data as long as your account is active and as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements. The retention duration depends on the purpose of data collection and any legal obligations.”
!Who else can access your data?Ask the vendor

Even where the individual-licence training licence applies, GitHub states it does not permit sharing Inputs or Outputs with third-party AI model providers for those providers' independent training; GitHub's Affiliates (including Microsoft) may still use them under their own privacy and contractual obligations unless the user opts out.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Unless you opt out, GitHub's Affiliates may use your Inputs and Outputs under this license in accordance with their applicable privacy and contractual obligations. This license does not, however, permit GitHub or its Affiliates to share your Inputs or Outputs with third-party AI model providers for their own independent model training purposes.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
!Where is your data processed?Ask the vendor

Personal Data is stored and processed in the user's local region, the United States and other countries where GitHub, its affiliates, subsidiaries or subprocessors operate; transfers from the EU, UK and Switzerland to non-adequate countries generally rely on EU standard contractual clauses. No Copilot-specific residency option is described in the collected documents.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection.”
!What happens in a security incident?Ask the vendor

GitHub's Acceptable Use Policies reference an operating GitHub Bug Bounty program under which authorised security research is not treated as unauthorised access. No security-incident or breach-notification commitment appears in the collected documents.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedGitHub Acceptable Use Policies - GitHub Docs ↗retrieved Oct 5, 2026
“Please note, activities permitted under bug bounty programs, such as the GitHub Bug Bounty program , are not considered “unauthorized,” but must only affect the organization whose bug bounty program authorized the activity.”

Email to send the vendor9 items to confirm in writing

Subject: Supplier assessment: written confirmation requested for GitHub Copilot
Hello GitHub team,

We are assessing GitHub Copilot (GitHub) as part of our supplier review. Before we proceed, please confirm the following in writing:

1. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
2. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
3. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
4. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
5. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
6. Can you confirm whether Microsoft Azure or AWS is the actual platform provider?
7. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
8. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
9. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Business and Enterprise prompts are transient and single-purpose under the Product Specific TermsStrong

The GitHub Copilot Product Specific Terms (October 2024) state that Copilot Business and Enterprise prompts are encrypted in transit, used only to generate suggestions in real time, deleted once generated, not stored at rest without permission and not used for any other purpose, with three disclosed retention carve-outs (CLI and non-editor tools, requested private models, customer-configured extensions). The same terms bind the customer to GitHub's Data Protection Agreement by default and to the Microsoft AI Code of Conduct and Required Mitigations.

This is the strongest product-scoped data commitment in the collected set and, for the tiers it covers, points the opposite way from the consumer Terms of Service and the controller-scope Privacy Statement. The carve-outs are specific enough for a buyer to check against their own configuration.

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“A. Generally. GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“CLI and Other Tools. If you use GitHub Copilot tools that operate outside of your code editor, such as Copilot for the Command Line Interface, GitHub Copilot retains your Prompts to those tools to provide the service. Private Language Models. If you have requested a customized private language model, GitHub Copilot retains your Prompts to fine-tune your private model. Custom Settings. If you have configured GitHub Copilot to use alternative data handling, such as enabling interaction with third party extensions, GitHub Copilot will retain your Prompts based on that configuration.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“By using GitHub Copilot, you agree to the General Terms unless you and GitHub have another Agreement in place, and you agree to the Data Protection Agreement unless your Agreement with GitHub already includes a different data protection agreement.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Your use of GitHub Copilot is subject to the Acceptable Use Policies, the AI Code of Conduct, and the Required Mitigations.”
✗Training on customer data splits sharply by tier and by GitHub's roleGap

Three documents point in different directions for different scopes. (1) Copilot Individual and Free under the Terms of Service (effective 27 April 2026): Inputs and Outputs are licensed to GitHub and its Affiliates for model training by default, with a prospective account-settings opt-out; private repository content supplied as Input falls under the same rule; GitHub will not pass Inputs or Outputs to third-party model providers for their own training, but Affiliates such as Microsoft may use them. (2) Copilot Business and Enterprise under the (deprecated) Product Specific Terms: prompts are used for no purpose other than generating suggestions, and the Terms of Service expressly carve Customer Agreement and volume-licence customers out of the J.3 training licence. (3) The General Privacy Statement, which applies only where GitHub is data controller, says Personal Data including code, inputs and AI outputs is used to train models and may be shared with Microsoft for the same purpose; for organization-provided accounts GitHub is processor under the DPA, so this language does not describe Business or Enterprise customer content. Separately, Section D.4 of the Terms of Service licenses all hosted Your Content for training AI Features and Affiliates' models, outside the J.3 opt-out.

A buyer who reads the Privacy Statement or Terms of Service in isolation would conclude GitHub trains on everything; a buyer who reads only the Product Specific Terms would conclude it trains on nothing. Which conclusion is right depends on the plan, the purchase channel (direct or Microsoft agreement) and whether the account is organization-provided. Individual and Free users must act to opt out; Business and Enterprise buyers need the current terms in writing.

Question for vendor: For our plan (Copilot Business or Enterprise) and purchase channel, confirm in writing under the GitHub Generative AI Services Terms that prompts, code context, repository content and suggestions are not used to train or fine-tune any GitHub, Microsoft or third-party model, and whether any Copilot telemetry or feedback data is excluded from that commitment.

Evidence
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We use your Inputs to generate Outputs and provide the AI Features. You also grant GitHub and its Affiliates a license to collect and use your Inputs and Outputs to develop, train and improve artificial intelligence and machine learning models and technologies including those that power AI Features, unless (a) you opt out through your account settings, or (b) your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Unless you opt out, GitHub's Affiliates may use your Inputs and Outputs under this license in accordance with their applicable privacy and contractual obligations. This license does not, however, permit GitHub or its Affiliates to share your Inputs or Outputs with third-party AI model providers for their own independent model training purposes.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“The training and data-use provisions in Section J.3 apply only to individual licenses. If your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement, those agreements govern the use of your data in connection with AI Features and Section J.3 does not apply to you.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“If you provide your private repository content as Input to AI Features, we may use that Input to provide, develop, train, and improve the Service, including AI Features. Your ability to opt out under Section J.3 applies to this use of private repository content. We will not otherwise use your private repository contents to develop or improve the Service.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“You grant GitHub and our Affiliates the right to store, host, archive, parse, display, and make copies of Your Content as necessary to provide, develop, and improve the Service, including by training AI Features, and for the purpose of training, developing, and improving artificial intelligence and machine learning models and technologies of our Affiliates.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements.”
!Product Specific Terms deprecated since 5 March 2026; the replacement terms and the DPA were not collectedGap

The Product Specific Terms page carries a notice that it was deprecated effective 5 March 2026 and that new subscriptions and renewals are governed by the GitHub Generative AI Services Terms at gh.io/terms, which were not in the collected set. The GitHub Data Protection Agreement page fetched as a 262-character stub, and four URLs intended to reach trust, compliance and DPA pages resolved to unrelated user profiles and were disregarded. The Business and Enterprise data claims in this entry are therefore marked stale_or_superseded, and the Trust Center summary page (which names no SOC, ISO or FedRAMP attestation) is the only assurance evidence collected.

Seven months after deprecation, most Copilot Business and Enterprise subscriptions will have renewed onto the newer terms. Any favourable conclusion about transient prompts or no-training for those tiers rests on a superseded document until the current terms are obtained, and no independent security attestation could be assessed.

Question for vendor: Provide the current GitHub Generative AI Services Terms and the Data Protection Agreement clauses that govern Copilot prompt retention, training exclusion and breach notification, together with the Copilot Trust Center's current list of attestations (SOC 2, ISO/IEC 27001 or equivalent) and their scope.

Evidence
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“NOTE: These terms have been deprecated effective 5 March 2026. New subscriptions and renewals that occur on 5 March 2026 and later are not governed by this document, and are instead governed by the GitHub Generative AI Services Terms available at gh.io/terms .”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“By using GitHub Copilot, you agree to the General Terms unless you and GitHub have another Agreement in place, and you agree to the Data Protection Agreement unless your Agreement with GitHub already includes a different data protection agreement.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“A. Generally. GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.”
!AI inference providers are named at organisation level, but not mapped to Copilot requests or plansGap

GitHub's subprocessor list names Anthropic, OpenAI, xAI, Cerebras, Fireworks AI, Google Cloud, Microsoft Azure and AWS as authorised AI inference subprocessors, with processing locations, and commits to 30 days' advance notice of new subprocessors. The Copilot documentation acknowledges third-party agents, models and MCP servers operating alongside Copilot. However, none of the collected documents states which provider processes a Copilot prompt for a given plan, feature or region, or whether administrators can restrict the model set.

For a hosted assistant GitHub operates the whole request path, so the processing chain is disclosable; the list proves the chain exists but a buyer cannot tell from it whether their code is sent to one provider or several, or in which country. The list is scoped to DPA-governed Enterprise services, so Individual and Free users have no equivalent disclosure.

Question for vendor: Which AI inference subprocessors process Copilot prompts for our plan and region, can administrators restrict Copilot to specific models or providers, and does Fireworks AI's processing in Germany and Iceland or Azure's in Canada, Chile and Mexico apply to Copilot traffic?

Evidence
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
!Thin evidence for independent assurance, evaluation, incident handling and change managementGap

Four domains are assessed as partial rather than covered. Independent assurance rests only on GitHub's self-certification to the EU-U.S., UK and Swiss Data Privacy Frameworks, a transfer mechanism rather than a security or AI-management audit. Testing and evaluation is supported by a stated Responsible AI Impact Assessment, security and privacy reviews and a Transparency Report case study on Copilot, with no published results, benchmarks or red-teaming detail; the Terms of Service also exclude Beta Previews from the Service's normal security measures and auditing. Vulnerability and incident handling is supported only by a reference to the GitHub Bug Bounty program, with no breach-notification commitment collected. Change management covers contractual and subprocessor notice but not model or behaviour changes. No domain was marked not_applicable: Copilot is a hosted assistant and GitHub operates the request path, so each of these disclosures is one GitHub could supply. No domain was marked not_evidenced because each has at least an organisation-level disclosure in the collected set.

A buyer relying on this set cannot verify Copilot's security controls against an audited standard, cannot see how GitHub measured Copilot's safety rather than its productivity effect, and has no stated incident-notification window. These are gaps in the collected evidence as much as in GitHub's publishing, given the Trust Center detail and DPA were not retrieved.

Question for vendor: Provide the SOC 2 Type II or ISO/IEC 27001 report scope covering Copilot, a summary of Copilot safety evaluations and red-teaming, the DPA security-incident notification timeline, and how customers are notified of model or behaviour changes to Copilot.

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“GitHub follows Microsoft's Responsible AI Standard in designing, building, and testing its AI systems in our products. The Microsoft RAI Standard has six principles–accountability, transparency, fairness, reliability & safety, privacy & security, and inclusiveness–that product teams consider in order to responsibly develop and deploy generative AI systems.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“GitHub has completed a Responsible AI Impact Assessment as well as security and privacy reviews to map different risks associated with its AI products.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“The report includes a case study on how GitHub mapped and managed key risks and measured the effectiveness of GitHub Copilot and Copilot Chat on developer productivity.”
Vendor publishedGitHub Acceptable Use Policies - GitHub Docs ↗retrieved Oct 5, 2026
“Please note, activities permitted under bug bounty programs, such as the GitHub Bug Bounty program , are not considered “unauthorized,” but must only affect the organization whose bug bounty program authorized the activity.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We will notify our Users of material changes to this Agreement, such as price increases, at least 30 days prior to the change taking effect by posting a notice on our Website or sending email to the primary email address specified in your GitHub account.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“GitHub Copilot is under active development. From time to time, GitHub may allow you to opt in to experimental functionality or to preview experimental Copilot services that are not generally available. If you choose to participate in such a preview, your use of pre-release software or services will not be governed by this document and will instead be governed by GitHub's standard pre-release license terms.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Beta Previews may not be supported and may be changed at any time without notice. In addition, Beta Previews are not subject to the same security measures and auditing to which the Service has been and is subject.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
!Declared Microsoft Azure, technically observed AWSGap

The vendor's own materials name Microsoft Azure as the platform provider, but DNS, certificate, or HTTP evidence points to AWS in that role instead.

A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.

Question for vendor: Can you confirm whether Microsoft Azure or AWS is the actual platform provider?

Evidence
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“If you use Copilot through an organization or enterprise, administrators decide how it can be used. They control which members have access, set policies for which features are available, exclude files that Copilot shouldn't see, and review usage data and audit logs to understand how it's being used.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“GitHub follows Microsoft's Responsible AI Standard in designing, building, and testing its AI systems in our products. The Microsoft RAI Standard has six principles–accountability, transparency, fairness, reliability & safety, privacy & security, and inclusiveness–that product teams consider in order to responsibly develop and deploy generative AI systems.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“Within GitHub, our Responsible AI Champions help map, measure, and manage risks associated with using generative AI in coding.”

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score47
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub Copilot is an AI assistant that helps you write, understand, and ship software. It suggests code as you type, answers questions about a codebase, reviews your changes, and works on tasks you assign it.”
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“Agentic. You describe a goal, and Copilot can work through multiple steps. It researches a repository, proposes a plan, edits files, reviews pull requests, runs tools, and prepares tasks for your review. You remain responsible for reviewing and approving.”
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“GitHub has completed a Responsible AI Impact Assessment as well as security and privacy reviews to map different risks associated with its AI products.”
Vendor publishedGitHub Trust Center · GitHub ↗retrieved Oct 5, 2026
“The report includes a case study on how GitHub mapped and managed key risks and measured the effectiveness of GitHub Copilot and Copilot Chat on developer productivity.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Beta Previews may not be supported and may be changed at any time without notice. In addition, Beta Previews are not subject to the same security measures and auditing to which the Service has been and is subject.”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We will notify our Users of material changes to this Agreement, such as price increases, at least 30 days prior to the change taking effect by posting a notice on our Website or sending email to the primary email address specified in your GitHub account.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“GitHub Copilot is under active development. From time to time, GitHub may allow you to opt in to experimental functionality or to preview experimental Copilot services that are not generally available. If you choose to participate in such a preview, your use of pre-release software or services will not be governed by this document and will instead be governed by GitHub's standard pre-release license terms.”

AI system description: vendor-evidenced, not yet independently corroborated.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedAbout GitHub Copilot - GitHub Docs ↗retrieved Oct 5, 2026
“External AI agents, models, and tools. Coding agents, models, and tools, including MCP servers from other providers, work alongside Copilot. Third-party coding agents work asynchronously on development tasks and can make changes and open or update pull requests for your review. They are subject to the same security protections, mitigations, and limitations as Copilot.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
Customer data15% of the score57
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“A. Generally. GitHub Copilot sends an encrypted Prompt from you to GitHub to provide Suggestions to you. Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose. Prompts are encrypted during transit and are not stored at rest without your permission.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Except as detailed below, Prompts are transmitted only to generate Suggestions in real-time, are deleted once Suggestions are generated, and are not used for any other purpose.”
Stale or supersededCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“CLI and Other Tools. If you use GitHub Copilot tools that operate outside of your code editor, such as Copilot for the Command Line Interface, GitHub Copilot retains your Prompts to those tools to provide the service. Private Language Models. If you have requested a customized private language model, GitHub Copilot retains your Prompts to fine-tune your private model. Custom Settings. If you have configured GitHub Copilot to use alternative data handling, such as enabling interaction with third party extensions, GitHub Copilot will retain your Prompts based on that configuration.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“We use your Inputs to generate Outputs and provide the AI Features. You also grant GitHub and its Affiliates a license to collect and use your Inputs and Outputs to develop, train and improve artificial intelligence and machine learning models and technologies including those that power AI Features, unless (a) you opt out through your account settings, or (b) your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“Unless you opt out, GitHub's Affiliates may use your Inputs and Outputs under this license in accordance with their applicable privacy and contractual obligations. This license does not, however, permit GitHub or its Affiliates to share your Inputs or Outputs with third-party AI model providers for their own independent model training purposes.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“If you provide your private repository content as Input to AI Features, we may use that Input to provide, develop, train, and improve the Service, including AI Features. Your ability to opt out under Section J.3 applies to this use of private repository content. We will not otherwise use your private repository contents to develop or improve the Service.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“You grant GitHub and our Affiliates the right to store, host, archive, parse, display, and make copies of Your Content as necessary to provide, develop, and improve the Service, including by training AI Features, and for the purpose of training, developing, and improving artificial intelligence and machine learning models and technologies of our Affiliates.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Product Development and Improvement: We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“We’ll retain your Personal Data as long as your account is active and as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements. The retention duration depends on the purpose of data collection and any legal obligations.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub stores and processes Personal Data in a variety of locations, including your local region, the United States, and other countries where GitHub, its affiliates, subsidiaries, or subprocessors have operations. We transfer Personal Data from the European Union, the United Kingdom, and Switzerland to countries that the European Commission has not recognized as having an adequate level of data protection.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Affiliates: Personal Data may be shared with GitHub affiliates, including Microsoft, to facilitate customer service, marketing and advertising, order fulfillment, billing, technical support, legal and compliance obligations, product development and improvement (including training and improving artificial intelligence and machine learning technologies), and for other purposes described in their respective privacy statements.”
AI supply chain10% of the scoreorganisation-level evidence75

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement . GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Amazon Web Services Inc (AWS) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States United States Anthropic PBC AI Inference and AI Services United States United States Cerebras Systems Inc. AI Inference and AI Services United States United States”
Externally corroboratedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“Fireworks AI AI Inference and AI Services United States, Germany, Iceland United States FullStory, Inc. Customer support ticketing analysis United States United States Google Cloud Platform (GCP) Cloud Hosted Infrastructure, AI Inference and AI Services United States, Belgium, Singapore United States Hewlett-Packard Limited Cloud Hosted Infrastructure United States United States LambdaTest Cloud Hosted Infrastructure United States United States Microsoft (Azure) Cloud Hosted Infrastructure, Data Hosting, AI Inference and AI Services United States, Canada, Chile, Mexico United States”
Vendor publishedGitHub Subprocessors - GitHub Docs ↗retrieved Oct 5, 2026
“OpenAI AI Inference and AI Services United States United States Oracle America, Inc. Cloud Hosted Infrastructure United States United States Pusher Building and managing real-time infrastructure for web and mobile applications United States United States Tines Automation Inc. Security management United States United States Twilio (SendGrid) SMS notification provider for 2 Factor Authentication United States United States xAI AI Inference and AI Services United States United States”
Security foundation15% of the scoreorganisation-level evidence64

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedGitHub Acceptable Use Policies - GitHub Docs ↗retrieved Oct 5, 2026
“Please note, activities permitted under bug bounty programs, such as the GitHub Bug Bounty program , are not considered “unauthorized,” but must only affect the organization whose bug bounty program authorized the activity.”
Independent assurance evidence10% of the scoreorganisation-level evidence63

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“GitHub has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2 ↗retrieved Oct 5, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“NOTE: These terms have been deprecated effective 5 March 2026. New subscriptions and renewals that occur on 5 March 2026 and later are not governed by this document, and are instead governed by the GitHub Generative AI Services Terms available at gh.io/terms .”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“These terms only apply to Copilot Business and Copilot Enterprise, and only when purchased directly from GitHub. If you purchase GitHub under a Microsoft agreement, these terms do not apply to you and your use of GitHub Copilot is instead governed by your Microsoft Product Terms, including the Microsoft Product Terms for GitHub Offerings. If you purchase GitHub Copilot Individual, these terms do not apply to you and your use of GitHub Copilot is instead governed by the GitHub Terms of Service, including the GitHub Privacy Statement and the GitHub Terms for Additional Products and Features.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“By using GitHub Copilot, you agree to the General Terms unless you and GitHub have another Agreement in place, and you agree to the Data Protection Agreement unless your Agreement with GitHub already includes a different data protection agreement.”
Vendor publishedCustomer agreements · GitHub ↗retrieved Oct 5, 2026
“Your use of GitHub Copilot is subject to the Acceptable Use Policies, the AI Code of Conduct, and the Required Mitigations.”
Vendor publishedGitHub Terms of Service - GitHub Docs ↗retrieved Oct 5, 2026
“The training and data-use provisions in Section J.3 apply only to individual licenses. If your use of the Service is governed by a GitHub Customer Agreement or volume licensing agreement, those agreements govern the use of your data in connection with AI Features and Section J.3 does not apply to you.”
Vendor publishedGitHub General Privacy Statement - GitHub Docs ↗retrieved Oct 5, 2026
“Should you access a GitHub Service through an account provided by an organization, such as your employer or school, the organization becomes the Data Controller, and this Privacy Statement's direct applicability to you changes. Even so, GitHub remains dedicated to preserving your privacy rights. In such circumstances, GitHub functions as a Data Processor, adhering to the Data Controller's instructions regarding your Personal Data's processing. A Data Protection Agreement governs the relationship between GitHub and the Data Controller.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Customer data treatment disclosureData 57 → 77
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 64 → 84
+3Verify EU-U.S. Data Privacy Framework scope covers this assessmentIndependent Assurance 63 → 84
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationOrganisation 60 → 72
+2Have Governance & accountability disclosures independently corroboratedOrganisation 60 → 75

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 58 → up to 79 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTUREGitHub, Inc.GitHub, Inc.GitHub CopilotGitHub CopilotAnthropic PBCAnthropic PBCOpenAIOpenAIxAIxAICerebras Systems Inc.Cerebras Systems Inc.Fireworks AIFireworks AIGoogle Cloud PlatformGoogle Cloud PlatformMicrosoft AzureMicrosoft AzureAmazon Web ServicesAmazon Web Services
View as list
GitHub, Inc. Contracted Subprocessor Anthropic PBC
GitHub, Inc. Contracted Subprocessor Cerebras Systems Inc.
GitHub, Inc. Contracted Subprocessor Amazon Web Services
GitHub, Inc. Uses Infrastructure Amazon Web Services
GitHub, Inc. Contracted Subprocessor Fireworks AI
GitHub, Inc. Contracted Subprocessor Google Cloud Platform
GitHub, Inc. Uses Infrastructure Google Cloud Platform
GitHub, Inc. Contracted Subprocessor Microsoft Azure
GitHub, Inc. Uses Infrastructure Microsoft Azure
GitHub, Inc. Contracted Subprocessor OpenAI
GitHub, Inc. Contracted Subprocessor xAI

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 5 — registry checks and verification ladders, click to view
EU-U.S. Data Privacy Framework (with UK Extension and Swiss-U.S. DPF)Vendor claimed only

Self-certification to the U.S. Department of Commerce covering GitHub's processing of personal data received from the EU, UK and Switzerland; a transfer mechanism, not an audit of security or AI-management controls. Organisation-wide; no Copilot-specific attestation collected.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Oct 5, 2026: Verified on the registry

Sources 19 — click to view
About GitHub Copilot - GitHub Docs
AI Documentation · Vendor · retrieved Oct 5, 2026
Trust · GitHub
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
dpa (M K) · GitHub
DPA · Vendor · retrieved Oct 5, 2026
GitHub Subprocessors - GitHub Docs
Subprocessor List · Vendor · retrieved Oct 5, 2026
GitHub General Privacy Statement - GitHub Docs
Privacy Notice · Vendor · retrieved Oct 5, 2026
Compliance · GitHub
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
GitHub Docs
Product Documentation · Vendor · retrieved Oct 5, 2026
Responsible use of GitHub Copilot features - GitHub Docs
AI Documentation · Vendor · retrieved Oct 5, 2026
gdpr · GitHub
DPA · Vendor · retrieved Oct 5, 2026
GitHub Trust Center · GitHub
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Privacy Policies - GitHub Docs
DPA · Vendor · retrieved Oct 5, 2026
Customer agreements · GitHub
Terms · Vendor · retrieved Oct 5, 2026
Privacy Policies - GitHub Docs
DPA · Vendor · retrieved Oct 5, 2026
GitHub Terms of Service - GitHub Docs
Terms · Vendor · retrieved Oct 5, 2026
GitHub Acceptable Use Policies - GitHub Docs
Terms · Vendor · retrieved Oct 5, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.