Is this your company?Buyers are checking Trust here. Claim trust.page free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Welcome to the [GitHub Copilot Trust Center](https://youtu.be/ydZxO1otlCQ), we are excited you are here. We enable developers and organizations to maximize their potential by prioritizing security, privacy, compliance, and transparency as we develop and iterate on GitHub Copilot.
Suggestions: These are the AI-generated code lines or chat responses provided to users based on their prompts.Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets.Prompts: These are inputs for chat or code, along with context, sent to Copilot's AI to generate suggestions.User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics.
Enterprise AI has moved from experimentation to production with measurable impact. Programs are delivering ~3.7x ROI, and over 80% of Fortune 500 companies are operating AI agents in core workflows. As adoption scales, governance becomes the limiter. Durable ROI depends on embedding responsible AI into the development lifecycle. Enterprise-grade AI governance at scale GitHub is extending ISO/IEC 42001:2023 certification across the GitHub Copilot portfolio, reinforcing our commitment to independently audited, responsible AI practices. In practice, whether customers use Copilot for developer productivity, enterprise workflows, or custom agents, the same consistent governance controls and assurance model apply.
GitHub now provides a warning about hidden Unicode textMay 2025
May 1, 2025 A warning is now displayed when a file’s contents include hidden Unicode text on github.com. Such text can be interpreted differently than it appears in a user interface. For example, hidden Unicode characters can hide text in a file. This can cause code to appear one way and be interpreted another way, especially by AI. To review a file for which this warning is displayed, open it in an editor that will display the hidden Unicode characters, like Visual Studio Code which highlights the characters by default. Then, verify that the characters are necessary and not disguising text that will be interpreted or compiled differently than it appears. For more information, refer to Pillar Security: Rules File Backdoor and Hiding and Finding Text with Unicode Tags.
This listing is partial
5/11 details · 45%
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Trust SOC 2 compliant?
Trust is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Trust SOC 3 compliant?
According to Trust's public trust center, Trust is SOC 3 compliant. On SOC2C this listing is Listed.
Is Trust ISO 27001 certified?
According to Trust's public trust center, Trust is ISO 27001 certified. On SOC2C this listing is Listed.
Is Trust CSA STAR certified?
According to Trust's public trust center, Trust is CSA STAR certified. On SOC2C this listing is Listed.
Is Trust ISO 42001 certified?
According to Trust's public trust center, Trust is ISO 42001 certified. On SOC2C this listing is Listed.
Is Trust SOC 2 Type I or Type II?
Trust is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Trust's SOC 2 for a vendor risk assessment?
Yes. Trust's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Trust penetration tested?
Trust hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Trust's SOC 2 report?
Trust's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Does Trust have a SOC 3 report?
Trust publishes a SOC 3 report, which is publicly shareable. Request access through SOC2C.
Is Trust secure?
Security isn't a single yes/no, but Trust is SOC 2 Type II compliant and holds SOC 2 Type II, SOC 3, ISO 27001, CSA STAR, ISO 42001. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Trust have a bug bounty or vulnerability disclosure program?
Trust hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@trust.page or via a /security page.
Who are Trust's subprocessors?
Trust's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Trust host or store data?
Trust's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Trust's trust center or security page?
Trust's trust center is at https://copilot.github.trust.page;ghec.github.trust.page. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How is Copilot data encrypted and protected during transit?
GitHub Copilot transmits data to GitHub’s Azure tenant or another model provider to generate outputs, including both contextual data about the code and file being edited (“inputs”) and data about the user’s actions (“user engagement data”). The transmitted data is encrypted both in transit and at rest; Copilot-related data is encrypted in transit using transport layer security (TLS), and for any data we retain at rest using Microsoft Azure’s data encryption (FIPS Publication 140-2 standards).
What third party testing and certifications does GitHub Copilot have?
- Audits and Certifications: Compliance reports are available for GitHub Copilot Business and Copilot Enterprise. Specifically, GitHub has published a SOC 2 Type I report for Copilot Business (including code completion in the IDE, and chat in the IDE, CLI, and Mobile). This Type 1 report demonstrates that Copilot Business has the controls in place necessary to protect the security of the service. Copilot Business and Copilot Enterprise was included in our latest SOC 2 Type 2. - Additionally, Copilot Business and Copilot Enterprise are now included in the scope of GitHub’s Information Security Management System, as reflected in our ISO 27001 certificate. This certification demonstrates that Copilot Business and Copilot Enterprise are developed and operated using the same security processes and standards as the rest of GitHub’s products. - External Penetration Test: GitHub can provide, under NDA to our current Enterprise customers, a third-party penetration and application test report from the assessment performed on GitHub Copilot for Business. Additionally, GitHub Copilot is in scope for GitHub’s Bug Bounty program.
How can I help keep GitHub Copilot secure?
- You can help by using GitHub Copilot and sharing feedback in the feedback forum. Please also report incidents (e.g., offensive output, code vulnerabilities, apparent personal information in code generation) directly to [copilot-safety@github.com](mailto:copilot-safety@github.com) so that we can improve our safeguards. GitHub takes safety and security very seriously and we are committed to continually improving. - Copilot is included in the GitHub Bug Bounty program. Copilot submissions are triaged and processed through the existing bug bounty workstreams.
How does GitHub Copilot aid in secure development?
- As outputs are generated and before they are returned to the user, Copilot applies an AI-based vulnerability prevention system that blocks insecure coding patterns in real-time to make Copilot outputs more secure. Our model targets the most common vulnerable coding patterns, including hardcoded credentials, SQL injections, and path injections. - The system leverages LLMs to approximate the behavior of static analysis tools and can even detect vulnerable patterns in incomplete fragments of code. This means insecure coding patterns can be quickly blocked and replaced by alternative outputs. - The best way to build secure software is through a secure software development lifecycle (SDLC). GitHub offers solutions to assist with other aspects of security throughout the SDLC, including code scanning (SAST), secret scanning, and dependency management (SCA). We recommend enabling features like branch protection to ensure that code is merged into your codebase only after it has passed your required tests and peer review.
How does GitHub Copilot work with other security measures?
- Proxies for filtering, e.g., PII: Outbound requests contain a prompt which is made up of code in the currently edited file and related files. If this request is _dropped_, then Copilot will fail to provide a completion and may show an error message. If the request is modified through operation of a proxy filter that removes personal information or questionable content or code, then Copilot is able to process the request as normal. - Air-gapped environments. GitHub Copilot for Business / Copilot for Enterprise requires an active internet connection between a user’s IDE and the GitHub Copilot Proxy service. As a result, it does not work in air-gapped environments.
What are limitations of GitHub Copilot?
While our experiments have shown that GitHub Copilot outputs code of the same or better quality than the average developer, we can’t give any assurance that the code is bug free. Like any programmer, Copilot may sometimes output insecure code. We recommend taking the same precautions you take with the code written by your engineers (linting, code scanning, IP scanning, etc.)
What security resources can I use to learn more?
- Microsoft secure software development lifecycle practices - GitHub security - Microsoft security products - General security at home - Preventing unauthorized access
What personal data does GitHub Copilot process?
GitHub Copilot processes personal data based on how Copilot is accessed and used: whether via github.com, mobile app, extensions, or one of various IDE extensions, or through features like outputs for the command line interface (CLI), IDE code completions, or personalized chat on GitHub.com. The types of personal data processed may include: - User Engagement Data: This includes pseudonymous identifiers captured on user interactions with Copilot, such as accepted or dismissed completions, error messages, system logs, and product usage metrics. - Input: means the data provided to GitHub Copilot, including prompts, attachments, code in the workspace, and conversation history. - Output: means responses and suggestions, including code or other material, generated by an AI Feature. - Feedback Data: This comprises real-time user feedback, including reactions (e.g., thumbs up/down) and optional comments, along with feedback from support tickets. Feedback data is retained as long as necessary.
How does GitHub use the Copilot data from Business and Enterprise Subscribers?
How GitHub uses Copilot data depends on how the user accesses Copilot and for what purpose. Users can access GitHub Copilot through the web, extensions, mobile apps, computer terminal, and various IDEs (Integrated Development Environments). GitHub generally uses personal data to: - Deliver, maintain, and update the services as per the customer's configuration and usage, to ensure personalized experiences and recommendations - Troubleshoot, which involves preventing, detecting, resolving, and mitigating issues, including security incidents and product-related problems, by fixing software bugs and maintaining the online services' functionality and up-to-dateness - Enhance user productivity, reliability, effectiveness, quality, privacy, accessibility, and security by keeping the service current and operational These practices are outlined in GitHub’s Data Protection Agreement (DPA), which details our data handling commitments to our data controller customers. As an independent data controller, as expressly provided in GitHub's Data Protection Agreement, GitHub also processes certain personal data for the following purposes: - Billing and account management - To comply with and resolve legal obligations - For abuse detection, prevention, and protection, virus scanning, and scanning to detect violations of terms of service. This processing may occur without separate customer instruction where GitHub determines it is necessary to protect the security and integrity of the Online Services. - To generate summary reports for calculating employee commissions and partner incentives - To produce aggregated reports for internal use and strategic planning, covering areas like forecasting, revenue analysis, capacity planning, and product strategy, For details on GitHub's data processing activities as a controller, particularly for Copilot Pro and Copilot Free customers, refer to the GitHub Terms for Additional Products and Features.
What is GitHub’s Processing Role for Copilot Business and Enterprise data (controller or processor)?
Data Processor GitHub acts primarily as a data processor in providing the Copilot Business and Enterprise services. In that capacity, GitHub uses personal data on behalf of our customers (the data controllers): - To deliver, maintain, and update the services as per the customer's configuration and usage, to ensure personalized experiences and recommendations - To troubleshoot, which involves preventing, detecting, resolving, and mitigating issues, including security incidents and product-related problems, by fixing software bugs and maintaining the online services' functionality and up-to-dateness - To enhance user productivity, reliability, effectiveness, quality, privacy, accessibility, and security by keeping the service current and operational GitHub’s data handling commitments for Copilot Business and Copilot Enterprise are in GitHub’s Data Protection Agreement (DPA). Data Controller After authorization through a DPA, GitHub may also process some personal data as a data controller. This is a complete list of those purposes: - For billing and account management - To generate summary reports for calculating employee commissions and partner incentives - To comply with and resolve legal obligations - For abuse detection, prevention, and protection, virus scanning, and scanning to detect violations of terms of service - To produce aggregated reports for internal use and strategic planning, covering areas like forecasting, revenue analysis, capacity planning, and product strategy, The details on the precise data involved depends on the access method and purpose. Users can access GitHub Copilot through the web, extensions, mobile apps, various IDEs (Integrated Development Environments), and features like CLI (Command Line Interface) chat, IDE code completions, or personalized chat on GitHub.com. For more information on GitHub’s processing as a data controller (e.g., Copilot Pro and Copilot Free customers), see the GitHub Terms for Additional Products and Features.
Does GitHub Copilot support compliance with the GDPR and other data protection laws?
Yes. GitHub and customers can enter into a Data Protection Agreement that supports compliance with the GDPR and similar legislation.
How long does GitHub retain Copilot data for Business and Enterprise customers?
If and for how long GitHub’s retains Copilot data depends on how a Copilot user accesses Copilot and for what purpose. The default settings for Copilot Business and Enterprise Customers are as follows: Access through IDE for Chat, Code Completions, and Copilot CLI: - Inputs and Outputs: Not retained by default. GitHub may retain input and output data for a limited period where necessary to investigate confirmed violations of GitHub's Acceptable Use Policies or Terms of Service, or to protect the security and integrity of the Online Services. Such retention is targeted, time-limited, and conducted in accordance with GitHub's Data Protection Agreement. - User Engagement Data: Kept for two years. - Feedback Data: Stored for as long as needed for its intended purpose. Note: Certain Copilot CLI commands may result in writing inputs or outputs to GitHub repositories. Learn more about Copilot CLI commands here. Other GitHub Copilot access and use: - Inputs and Outputs: Retained for up to 28 days by default. GitHub may retain input and output data beyond this period, or enable retention where it would not otherwise occur, where necessary to investigate confirmed violations of GitHub's Acceptable Use Policies or Terms of Service, or to protect the security and integrity of the Online Services. Such retention is targeted, time-limited, and conducted in accordance with GitHub's Data Protection Agreement. - User Engagement Data: Kept for two years. - Feedback Data: Stored for as long as needed for its intended purpose. For Copilot Coding Agent, session logs are retained for the life of the account in order to provide the service.