Skip to main content
Skip to main content

GitHub Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about GitHub before GitHub sends a questionnaire or a security document.

GitHub's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from GitHub — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on GitHub's own trust page.

FedRAMP Certified — Class B (Low) Checked August 2026.

GitHub Enterprise Cloud is FedRAMP Certified at Class B (Low) via the Agency path (package FR1812058188). Class B is the Low baseline — GitHub does not hold a Moderate certification.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
25 of 26 sources returned data
Questionnaire
81 / 133 answered
61% from public evidence
Last assessed
Aug 28, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 2 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 18.9 years🟢Infrastructure: 3 open ports, 0 CVEs
FedRAMP Status
GitHub is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
GitHub — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
GitHub returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned GitHub a Moderate Risk tier across 26 intelligence sources, 25 of which returned usable evidence (evidence confidence 100%).

26 sources queried, 25 returning usable evidence. The GitHub assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest GitHub Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

81 questions answered before GitHub responds.

ThirdProof used public evidence to pre-fill 61% of a 133-question vendor security questionnaire — without waiting for GitHub. The remaining 52 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

GitHub is now PCI DSS v4.0 compliant as a service provider, with Attestation of Compliance (AoC) and shared responsibility matrix completed as of March 2025.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

GDPR compliance / DPA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

GitHub Enterprise covers a HIPAA BAA via Microsoft's agreement, and BAA agreements can be accessed through the Admin console under Security and Privacy Additional Terms section.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

GitHub encrypts sensitive database columns at rest using AES256-GCM encryption algorithm.

Public evidencehigh confidence

+ 76 additional evidence-backed answers

Get the Complete GitHub Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before GitHub sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • FedRAMP Authorization Independently Verified
  • FedRAMP Authorization Confirmed via Registry
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Zero Data Retention for AI Processing

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Access Control — 8 of 12 questions need vendor input
  • Incident Response — 7 of 10 questions need vendor input
  • Data Security — 5 of 14 questions need vendor input
  • Vulnerability Management — 5 of 8 questions need vendor input

Reviewing GitHub for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for GitHub

GitHub is a widely-used development platform owned by Microsoft, serving millions of developers and enterprises globally.

Area Requiring Attention

The platform demonstrates strong foundational security practices, with FedRAMP authorization (LI-SaaS), ISO 27001 certification, PCI DSS v4.0 compliance, and a published 99.9% uptime SLA. GitHub maintains a dedicated security leadership structure, enforces multi-factor authentication platform-wide, and encrypts sensitive data at rest using AES-256-GCM.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from public data without vendor participation or input.

Investigation Findings

4 findings identified for GitHub

1 critical3 medium
critical

Security incidents reported involving the vendor

[GitHub confirmed unauthorized access to approximately 3,800–4,000 internal repositories in May 2026, with stolen source code and organizational data offered for sale by threat actor TeamPCP](https://www.cpomagazine.com/cyber-security/github-hacker-claims-security-breach-involved-about-4000-internal-repositories-takes-bids-on-stolen-data/). [The breach was traced to a malicious 'Nx Console' VS Code extension that compromised a GitHub employee device](https://www.infosecurity-magazine.com/news/github-breach-nx-console-vs-code/), enabling unauthorized access to the vendor's own internal infrastructure and source repositories. …

medium

Regulatory action reported against the vendor

[GitHub was fined 3.5 million rubles by Russia's Tagansky Court in August 2026 for failing to remove prohibited content](https://www1.ru/en/news/2026/08/19/429088-github-ostrafovali-v-rossii-na-35-mln-rublei-za-zapreshhennyi-kontent.html). This regulatory action, though modest in financial terms, signals potential friction between GitHub's content policy enforcement and specific jurisdictional legal requirements. …

medium

Domain expiring soon

The domain registration for github.com expires in 42 days (October 9, 2026). The domain has been continuously registered since 2007, with MarkMonitor Inc. as the registrar. …

medium

Sensitive services exposed to internet

github.com exposes port 22 (SSH) to the internet in addition to standard web ports (80, 443). SSH exposure is typical for a developer platform and is necessary for Git protocol operations; however, it represents a network attack surface that should be monitored for abuse and intrusion attempts. …

Showing the 4 most severe of 5 findings.

Security Strengths

Evidence that positively supports GitHub's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

FedRAMP Authorization Confirmed via Registry

Certification Registry Verification

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Zero Data Retention for AI Processing

AI Data Usage Policy

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

GitHub complete vendor assessment

Tier 3
Moderate Risk
81 / 133
questionnaire answers
26
sources checked
Aug 28, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 28, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Frequently asked about GitHub

Does GitHub have SOC 2 Type II?+
GitHub states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is GitHub on the OFAC sanctions list?+
GitHub returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is GitHub's vendor risk tier?+
ThirdProof assigned GitHub a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 26 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning GitHub.
Has GitHub had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 1 incident-related finding for GitHub, of which 1 is rated high severity or above. The most severe concerns security incidents reported involving the vendor. Each finding states whether the incident affected GitHub's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is GitHub PCI DSS compliant?+
GitHub is now PCI DSS v4.0 compliant as a service provider, with Attestation of Compliance (AoC) and shared responsibility matrix completed as of March 2025. ThirdProof records this from GitHub's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does GitHub support HIPAA and sign BAAs?+
GitHub Enterprise covers a HIPAA BAA via Microsoft's agreement, and BAA agreements can be accessed through the Admin console under Security and Privacy Additional Terms section. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a GitHub security questionnaire?+
Yes. ThirdProof answered 81 of 133 questions (61%) about GitHub from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 52 are listed as open, so the follow-up you send GitHub is short and specific.
What evidence should I request from GitHub?+
Public evidence settles a large part of the review, so the request you send should be short. Ask GitHub for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on access control, incident response, data security; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking GitHub to re-confirm what is already documented.

If GitHub is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The GitHub assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required