SOC2C

Is this your company? Buyers are checking Trust here. Claim trust.page free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Trust logo

Trust

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Trust is SOC 2 Type II compliant. Trust also holds SOC 3, ISO 27001, CSA STAR, and ISO 42001.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to the [GitHub Copilot Trust Center](https://youtu.be/ydZxO1otlCQ), we are excited you are here. We enable developers and organizations to maximize their potential by prioritizing security, privacy, compliance, and transparency as we develop and iterate on GitHub Copilot.

Compliance & infrastructure

SOC 2 Type IISOC 3ISO 27001CSA STARISO 42001
Data handled
Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts.Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets.Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions.User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.

Documents

16

Compliance leadership

The person who leads Trust's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Trust's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

GitHub achieves ISO/IEC 42001 CertificationMar 2026

Enterprise AI has moved from experimentation to production with measurable impact. Programs are delivering ~3.7x ROI, and over 80% of Fortune 500 companies are operating AI agents in core workflows. As adoption scales, governance becomes the limiter. Durable ROI depends on embedding responsible AI into the development lifecycle. Enterprise-grade AI governance at scale GitHub is extending ISO/IEC 42001:2023 certification across the GitHub Copilot portfolio, reinforcing our commitment to independently audited, responsible AI practices. In practice, whether customers use Copilot for developer productivity, enterprise workflows, or custom agents, the same consistent governance controls and assurance model apply.

GitHub now provides a warning about hidden Unicode textMay 2025

May 1, 2025 A warning is now displayed when a file’s contents include hidden Unicode text on github.com. Such text can be interpreted differently than it appears in a user interface. For example, hidden Unicode characters can hide text in a file. This can cause code to appear one way and be interpreted another way, especially by AI. To review a file for which this warning is displayed, open it in an editor that will display the hidden Unicode characters, like Visual Studio Code which highlights the characters by default. Then, verify that the characters are necessary and not disguising text that will be interpreted or compiled differently than it appears. For more information, refer to Pillar Security: Rules File Backdoor and Hiding and Finding Text with Unicode Tags.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Trust SOC 2 compliant?
Trust is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Trust SOC 3 compliant?
According to Trust's public trust center, Trust is SOC 3 compliant. On SOC2C this listing is Listed.
Is Trust ISO 27001 certified?
According to Trust's public trust center, Trust is ISO 27001 certified. On SOC2C this listing is Listed.
Is Trust CSA STAR certified?
According to Trust's public trust center, Trust is CSA STAR certified. On SOC2C this listing is Listed.
Is Trust ISO 42001 certified?
According to Trust's public trust center, Trust is ISO 42001 certified. On SOC2C this listing is Listed.