VendorScore · Developer tools · Data-access posture

Can GitHub read your private repositories and Copilot code?

A plain-language answer from GitHub's public Terms, Privacy Statement, Copilot docs and subprocessor list. GitHub holds the encryption keys for hosted repositories.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, GitHub can read your private repositories by design (with controls). GitHub holds the keys and its terms allow personnel access for security, scanning, support, integrity and legal reasons. Copilot Business/Enterprise data isn't used for training, and IDE prompts aren't retained, but other Copilot surfaces keep prompts for 28 days.

52 / 100 overall

Scored configuration: GitHub Enterprise Cloud (Corporate Terms / Customer Agreement + DPA), optionally with data residency on GHE.com, plus Copilot Business or Enterprise. No customer-managed key option was found, so the default and scored configuration match for key custody.

Report confidence: Medium. GitHub's DPA and the Copilot Trust Center couldn't be fetched and weren't reviewed.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in GitHub's public documentation:

  • GitHub's Data Protection Agreement returned an error and wasn't reviewed; DPA-specific terms such as audit rights and objection mechanics are Unknown from the primary source.
  • The Copilot Trust Center returned an error page; Copilot-specific certifications are Unknown.
  • The main public evidence for repository encryption at rest is a 2019 changelog.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: GitHub data access, AI training, GDPR and residency

Can GitHub read your private repositories and Copilot code?

Yes, GitHub can read your private repositories by design (with controls). GitHub holds the keys and its terms allow personnel access for security, scanning, support, integrity and legal reasons. Copilot Business/Enterprise data isn't used for training, and IDE prompts aren't retained, but other Copilot surfaces keep prompts for 28 days. VendorScore rates GitHub 52/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: GitHub Enterprise Cloud (Corporate Terms / Customer Agreement + DPA), optionally with data residency on GHE.com, plus Copilot Business or Enterprise. No customer-managed key option was found, so the default and scored configuration match for key custody.

Is GitHub encrypted at rest? Does GitHub offer BYOK?

GitHub says "Source code stored on GitHub.com will be encrypted at rest, by default" (2019 changelog), and it encrypts sensitive database columns with keys held in GitHub's environment. We found no BYOK, EKM or customer-managed key option for GitHub-hosted repositories, including in the data-residency docs. No algorithm for git storage is stated, and there's no E2EE.

Can GitHub employees see my private repositories?

Yes, in listed situations. GitHub's Terms of Service say personnel "will not access private repository content without your consent except" for security purposes, automated scanning or manual review for malware and known violations, to assist with a support matter, to maintain service integrity, or for legal compliance. GitHub gives notice of such access except for legal disclosure, automated scanning or security threats. The Corporate Terms point to the same rules.

Does GitHub Copilot train on my code?

Not on Copilot Business or Enterprise. GitHub says: "GitHub does not use Copilot Business or Copilot Enterprise customer data to train AI models." For Copilot Free, Pro and Pro+, GitHub may use interactions to train its models unless the user opts out. On Business and Enterprise, IDE chat and code-completion prompts aren't retained; prompts from other Copilot surfaces are kept for 28 days.

Is GitHub GDPR compliant? Where is the GitHub DPA?

VendorScore doesn't certify compliance; GitHub publishes a Data Protection Agreement at https://github.com/customer-terms/github-data-protection-agreement. We link GitHub's DPA page but did not review its content: the page returned an error when we tried to fetch it, so its audit and objection terms are Unknown here. GitHub's Copilot docs say Copilot Business and Enterprise data is protected under that DPA.

Who are GitHub's subprocessors, and do AI vendors see my code?

GitHub's list for services under its DPA (with at least 30 days' notice of new subprocessors) includes AWS, Azure, GCP, Oracle, Hewlett-Packard, Elasticsearch, Cloudflare and Fastly, plus AI inference vendors Anthropic, Cerebras, Fireworks AI, OpenAI and xAI, which may receive Copilot prompts that contain code. GitHub cites zero-data-retention agreements with OpenAI and, for generally available features, Anthropic, with named exceptions. The list is published at https://docs.github.com/en/site-policy/privacy-policies/github-subprocessors.

Can I keep GitHub data in the EU (data residency)?

Yes, with GitHub Enterprise Cloud with data residency (a GHE.com subdomain), which offers the EU (including Azure regions in Norway and Switzerland), Australia, the US and Japan. By default, GitHub.com data is stored in the USA.

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (github.md), evidence dated 2026-10-07.