GitHub Copilot

github.com

Public evidence identified as at Aug 31, 2026

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
Not scored — insufficient public evidence

Security review required

A score is only published when there is evidence to score.

Before you sign

The Copilot trust portal could not be read, and it holds the answersBlocking

Why it matters: GitHub runs a dedicated Copilot trust portal, which returned no readable content to this collection across repeated attempts. What remains is the GitHub-wide privacy statement and subprocessor list, neither scoped to Copilot.

What to ask for: Please provide the GitHub Copilot Trust Center documentation covering prompt and suggestion retention, human review, and whether Business and Enterprise content is excluded from model training.

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

GitHub's general privacy statement reserves use of personal data to develop and improve its products and technologies, including training models, with aggregation and de-identification where feasible. The statement is organisation-wide and not scoped to Copilot.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
!How long do they keep your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!Who else can access your data?Ask the vendor

GitHub publishes a subprocessor list governed by the GitHub Data Protection Agreement and publishes new subprocessors in advance.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
Where is your data processed?Clear

GitHub states Copilot can enforce geographic data residency for GitHub Enterprise Cloud customers with such requirements.

Evidence
Vendor publishedWhat is GitHub Copilot? - GitHub Docsretrieved Aug 31, 2026
For enterprises and organizations with data residency requirements: If you use GitHub Enterprise Cloud, Copilot can enforce geographic data residency. See GitHub Copilot with data residency .
!What happens in a security incident?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Confirm in writing: Ask the vendor to state this in writing before signing.

Key findingsclick a row for the evidence

The Copilot trust portal could not be read, and it holds the answersGap

GitHub runs a dedicated Copilot trust portal, which returned no readable content to this collection across repeated attempts. What remains is the GitHub-wide privacy statement and subprocessor list, neither scoped to Copilot.

Copilot's specific commitments — whether prompts and suggestions train models, how that differs between individual and Business or Enterprise plans, and retention — live in the portal that could not be read. This assessment is incomplete on those points; that is a statement about our collection, not about GitHub's posture.

Question for vendor: Please provide the GitHub Copilot Trust Center documentation covering prompt and suggestion retention, human review, and whether Business and Enterprise content is excluded from model training.

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
!The only training language found is organisation-wideGap

GitHub's general privacy statement reserves use of personal data for developing and improving products including training models. It governs GitHub as a whole and names Copilot only as one feature among several.

This clause can neither clear nor condemn Copilot. GitHub's published Copilot-specific position has historically been more restrictive than its general statement, so reading the general clause as Copilot policy would misrepresent it in both directions.

Question for vendor: Does the general privacy statement's training reservation apply to Copilot prompts and suggestions, and does the answer differ by plan?

Evidence
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
Data residency exists, tied to the Enterprise Cloud tierStrong

Copilot can enforce geographic data residency for GitHub Enterprise Cloud customers.

Residency control is a real capability for regulated buyers, but it is a procurement decision rather than a setting every Copilot customer can reach.

Question for vendor: Which regions are supported, and does residency cover prompts and suggestions as well as repository content?

Evidence
Vendor publishedWhat is GitHub Copilot? - GitHub Docsretrieved Aug 31, 2026
For enterprises and organizations with data residency requirements: If you use GitHub Enterprise Cloud, Copilot can enforce geographic data residency. See GitHub Copilot with data residency .
!Path-guessing on github.com returns user profiles, not policiesGap

Several candidate sources on this domain are GitHub user profile pages reached at paths like /ai, /dpa and /aup, which are usernames on github.com rather than policy pages. They carry no assurance content.

Recorded so a reader can see why this assessment is thinner than others: the collection under-represents what GitHub publishes about Copilot, and the scan is worth re-running once the trust portal is retrievable.

Evidence
Vendor publishedWhat is GitHub Copilot? - GitHub Docsretrieved Aug 31, 2026
GitHub Copilot is an AI coding assistant that helps you write code faster and with less effort. Then, you can focus more energy on problem solving and collaboration.
?Technical dependency observed: Microsoft AzureObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft Azure as a platform provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft Azure appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
?Technical dependency observed: AWSObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on AWS as a platform provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — AWS appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .

AI System Assurance Report Cardscored per assurance object — organisational assurance is not product, model or agent assurance

Overall AI system assurance
Not scored — insufficient public evidence

Derived from the dimensions below — expand any row for the evidence behind its grade.

Organisation & AI governance15% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Not Evidenced

Governance & accountability: not publicly evidenced.

AI system15% of the score13
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedWhat is GitHub Copilot? - GitHub Docsretrieved Aug 31, 2026
GitHub Copilot is an AI coding assistant that helps you write code faster and with less effort. Then, you can focus more energy on problem solving and collaboration.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score52
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedWhat is GitHub Copilot? - GitHub Docsretrieved Aug 31, 2026
For enterprises and organizations with data residency requirements: If you use GitHub Enterprise Cloud, Copilot can enforce geographic data residency. See GitHub Copilot with data residency .
Vendor publishedGitHub General Privacy Statement - GitHub Docsretrieved Aug 31, 2026
We use Personal Data to develop and improve our products, services, and technologies, including artificial intelligence and machine learning technologies. This includes improving features, developing new offerings, enhancing safety and security capabilities, and training models. We apply appropriate technical safeguards, including aggregation and de-identification techniques where feasible, to protect your privacy while enabling these improvements.
AI supply chain10% of the scoreorganisation-level evidence40

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedGitHub Subprocessors - GitHub Docsretrieved Aug 31, 2026
subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement .
Security foundation15% of the scoreorganisation-level evidence24

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Not Evidenced

Vulnerability & incident handling: not publicly evidenced.

Independent assurance evidence10% of the scoreorganisation-level evidence63

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 31, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the scoreorganisation-level evidence0

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Not Evidenced

Legal & contractual transparency: not publicly evidenced.

Not graded: Agent — not applicable to this scan.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESGitHubGitHubGitHub CopilotGitHub Copilot
View as list
GitHub Uses AI Service GitHub Copilot

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 4 — registry checks and verification ladders, click to view
ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 31, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 31, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry

Sources 15 — click to view
What is GitHub Copilot? - GitHub Docs
AI Documentation · Vendor · retrieved Aug 31, 2026
Trust · GitHub
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
dpa (M K) · GitHub
DPA · Vendor · retrieved Aug 31, 2026
GitHub Subprocessors - GitHub Docs
Subprocessor List · Vendor · retrieved Aug 31, 2026
GitHub General Privacy Statement - GitHub Docs
Privacy Notice · Vendor · retrieved Aug 31, 2026
Compliance · GitHub
Certification Or Compliance Page · Vendor · retrieved Aug 31, 2026
GitHub Docs
Product Documentation · Vendor · retrieved Aug 31, 2026
aup (Pierre-Yves Vasener) · GitHub
Terms · Vendor · retrieved Aug 31, 2026
Responsible use of GitHub Copilot features - GitHub Docs
AI Documentation · Vendor · retrieved Aug 31, 2026
github.com Trust Center
Trust Or Security Page · Vendor · retrieved Aug 31, 2026
gdpr · GitHub
DPA · Vendor · retrieved Aug 31, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 31, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).
Requirements for bodies auditing/certifying AIMS · Published (Jul 2025) — turns AI management systems into a certification and assessor-competence conversation. Builds on ISO/IEC 17021-1.
Requirements for ISMS certification bodies · Certification-integrity baseline for audit bodies; the two-year transition concluded around March 2026.

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.