Q39
Are you PCI DSS compliant? At what level?
GitHub is now PCI DSS v4.0 compliant as a service provider, with Attestation of Compliance (AoC) and shared responsibility matrix completed as of March 2025.
ThirdProof independently checks public intelligence sources to show what your team can verify about GitHub before GitHub sends a questionnaire or a security document.
GitHub's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from GitHub — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on GitHub's own trust page.
✓ FedRAMP Certified — Class B (Low) Checked August 2026.
GitHub Enterprise Cloud is FedRAMP Certified at Class B (Low) via the Agency path (package FR1812058188). Class B is the Low baseline — GitHub does not hold a Moderate certification.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
26 sources queried, 25 returning usable evidence. The GitHub assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest GitHub Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 61% of a 133-question vendor security questionnaire — without waiting for GitHub. The remaining 52 are listed as open, so the follow-up you send is short and specific.
Q39
GitHub is now PCI DSS v4.0 compliant as a service provider, with Attestation of Compliance (AoC) and shared responsibility matrix completed as of March 2025.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
GitHub Enterprise covers a HIPAA BAA via Microsoft's agreement, and BAA agreements can be accessed through the Admin console under Security and Privacy Additional Terms section.
Q23
GitHub encrypts sensitive database columns at rest using AES256-GCM encryption algorithm.
+ 76 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing GitHub for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for GitHub
GitHub is a widely-used development platform owned by Microsoft, serving millions of developers and enterprises globally.
The platform demonstrates strong foundational security practices, with FedRAMP authorization (LI-SaaS), ISO 27001 certification, PCI DSS v4.0 compliance, and a published 99.9% uptime SLA. GitHub maintains a dedicated security leadership structure, enforces multi-factor authentication platform-wide, and encrypts sensitive data at rest using AES-256-GCM.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from public data without vendor participation or input.
4 findings identified for GitHub
[GitHub confirmed unauthorized access to approximately 3,800–4,000 internal repositories in May 2026, with stolen source code and organizational data offered for sale by threat actor TeamPCP](https://www.cpomagazine.com/cyber-security/github-hacker-claims-security-breach-involved-about-4000-internal-repositories-takes-bids-on-stolen-data/). [The breach was traced to a malicious 'Nx Console' VS Code extension that compromised a GitHub employee device](https://www.infosecurity-magazine.com/news/github-breach-nx-console-vs-code/), enabling unauthorized access to the vendor's own internal infrastructure and source repositories. …
[GitHub was fined 3.5 million rubles by Russia's Tagansky Court in August 2026 for failing to remove prohibited content](https://www1.ru/en/news/2026/08/19/429088-github-ostrafovali-v-rossii-na-35-mln-rublei-za-zapreshhennyi-kontent.html). This regulatory action, though modest in financial terms, signals potential friction between GitHub's content policy enforcement and specific jurisdictional legal requirements. …
The domain registration for github.com expires in 42 days (October 9, 2026). The domain has been continuously registered since 2007, with MarkMonitor Inc. as the registrar. …
github.com exposes port 22 (SSH) to the internet in addition to standard web ports (80, 443). SSH exposure is typical for a developer platform and is necessary for Git protocol operations; however, it represents a network attack surface that should be monitored for abuse and intrusion attempts. …
Showing the 4 most severe of 5 findings.
Evidence that positively supports GitHub's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Zero Data Retention for AI Processing
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →GitHub complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent GitHub? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The GitHub assessment above is already written; ask for it and it lands in your inbox.