GitHub is committed to developer privacy and provides a high standard of privacy protection to all our developers and customers. We apply stringent individual privacy protections to all GitHub users worldwide, regardless of their country of origin or location.
Trusted by millions of developers
We protect and defend the most trustworthy platform for developers everywhere to create and build software.
Secure platform, secure data
We’re constantly improving our security, audit, and compliance solutions with you in mind.
Platform
We keep GitHub safe, secure, and free of spam and abuse so that this can be the platform where developers come together to create.
Open source
We inspire and enable the community to secure open source at scale, so the world’s software we all depend on sits on foundations you can trust.
Customers
We help our customers' security and risk teams feel confident in their decisions to encourage developer collaboration on GitHub.
Security Highlights
GitHub maintains top-tier security with rigorous certifications and compliance measures to help protect your data.
- GitHub provides SOC 1 Type 2 and SOC 2 Type 2 reports, adhering to IAASB International Standards. Explore GitHub Copilot reports and GitHub Enterprise Cloud reports.
- GitHub’s ISMS is certified against ISO/IEC 27001:2013, supporting international customer programs. Explore GitHub Copilot certificates and GitHub Enterprise Cloud certificates.
Cloud security and compliance
GitHub is a Trusted Cloud Provider(™) with the Cloud Security Alliance (CSA), having completed the self-assessment and third-party assessment for Level 1 CSA STAR Registry and Level 2 STAR Certification. Government users can confidently host projects on GitHub Enterprise Cloud, knowing our platform meets the low impact SaaS security standards set by U.S. federal partners.
Ready for best-in-class enterprise security?
GitHub provides end-to-end DevSecOps, where security is embedded directly into the developer workflow—empowering you to ship secure software fast.