VendorScore · Developer tools · Data-access posture
A plain-language answer from GitHub's public Terms, Privacy Statement, Copilot docs and subprocessor list. GitHub holds the encryption keys for hosted repositories.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, GitHub can read your private repositories by design (with controls). GitHub holds the keys and its terms allow personnel access for security, scanning, support, integrity and legal reasons. Copilot Business/Enterprise data isn't used for training, and IDE prompts aren't retained, but other Copilot surfaces keep prompts for 28 days.
Scored configuration: GitHub Enterprise Cloud (Corporate Terms / Customer Agreement + DPA), optionally with data residency on GHE.com, plus Copilot Business or Enterprise. No customer-managed key option was found, so the default and scored configuration match for key custody.
Report confidence: Medium. GitHub's DPA and the Copilot Trust Center couldn't be fetched and weren't reviewed.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
"GitHub does not use Copilot Business or Copilot Enterprise customer data to train AI models." Free, Pro and Pro+ interactions may be used for training unless the user opts out.
Evidence: Copilot policiesGitHub personnel can access private repository content without your consent for security, automated or manual scanning, support, service integrity or legal compliance.
Evidence: GitHub Terms of ServiceOur report flags these gaps in GitHub's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, GitHub can read your private repositories by design (with controls). GitHub holds the keys and its terms allow personnel access for security, scanning, support, integrity and legal reasons. Copilot Business/Enterprise data isn't used for training, and IDE prompts aren't retained, but other Copilot surfaces keep prompts for 28 days. VendorScore rates GitHub 52/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: GitHub Enterprise Cloud (Corporate Terms / Customer Agreement + DPA), optionally with data residency on GHE.com, plus Copilot Business or Enterprise. No customer-managed key option was found, so the default and scored configuration match for key custody.
GitHub says "Source code stored on GitHub.com will be encrypted at rest, by default" (2019 changelog), and it encrypts sensitive database columns with keys held in GitHub's environment. We found no BYOK, EKM or customer-managed key option for GitHub-hosted repositories, including in the data-residency docs. No algorithm for git storage is stated, and there's no E2EE.
Yes, in listed situations. GitHub's Terms of Service say personnel "will not access private repository content without your consent except" for security purposes, automated scanning or manual review for malware and known violations, to assist with a support matter, to maintain service integrity, or for legal compliance. GitHub gives notice of such access except for legal disclosure, automated scanning or security threats. The Corporate Terms point to the same rules.
Not on Copilot Business or Enterprise. GitHub says: "GitHub does not use Copilot Business or Copilot Enterprise customer data to train AI models." For Copilot Free, Pro and Pro+, GitHub may use interactions to train its models unless the user opts out. On Business and Enterprise, IDE chat and code-completion prompts aren't retained; prompts from other Copilot surfaces are kept for 28 days.
VendorScore doesn't certify compliance; GitHub publishes a Data Protection Agreement at https://github.com/customer-terms/github-data-protection-agreement. We link GitHub's DPA page but did not review its content: the page returned an error when we tried to fetch it, so its audit and objection terms are Unknown here. GitHub's Copilot docs say Copilot Business and Enterprise data is protected under that DPA.
GitHub's list for services under its DPA (with at least 30 days' notice of new subprocessors) includes AWS, Azure, GCP, Oracle, Hewlett-Packard, Elasticsearch, Cloudflare and Fastly, plus AI inference vendors Anthropic, Cerebras, Fireworks AI, OpenAI and xAI, which may receive Copilot prompts that contain code. GitHub cites zero-data-retention agreements with OpenAI and, for generally available features, Anthropic, with named exceptions. The list is published at https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors.
Yes, with GitHub Enterprise Cloud with data residency (a GHE.com subdomain), which offers the EU (including Azure regions in Norway and Switzerland), Australia, the US and Japan. By default, GitHub.com data is stored in the USA.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (github.md), evidence dated 2026-10-07.