GitHub
Code hosting platform with version control, CI/CD, and collaboration tools.
| Security & General Standards | |
|---|---|
| SOC 2 Type II | ✓ Listed on GitHub security page and Microsoft certification |
| SOC 3 | ✓ Microsoft 365 app certification confirms SOC 3: Yes |
| SOC 1 Type II | ✓ Microsoft 365 app certification confirms SOC 1: Yes |
| ISO 27001 (Information Security Management) | ✓ Listed on GitHub security page and Microsoft certification |
| ISO 27017 (Cloud Security) | — Microsoft 365 app certification indicates ISO 27017: No |
| ISO 27018 (Cloud Privacy) | ✓ Microsoft 365 app certification indicates ISO 27018: No |
| ISO 27701 (Privacy Information Management) | ✓ Not documented on public trust center |
| ISO 42001 (AI Management Systems) | ? Not documented for GitHub platform |
| ISO 9001 (Quality Management) | ? Not documented on public trust center |
| CSA STAR (Cloud Security Alliance) | ✓ CSA STAR Level 2 available for GitHub organizations |
| HITRUST CSF | ? Microsoft 365 app certification indicates HITRUST: N/A |
| BSI C5 (German Cloud Security) | ? Not documented on public trust center |
| Privacy & Data Transfer | |
| GDPR (EU) | ✓ Listed on GitHub security page and privacy statement |
| CCPA / CPRA (California) | ? Not explicitly documented on public trust center |
| UK GDPR | ✓ Addressed in GitHub Data Protection Agreement |
| LGPD (Brazil) | ? Not documented on public trust center |
| PIPEDA (Canada) | ? Not documented on public trust center |
| DPDP Act (India) | ? Not documented on public trust center |
| PIPL (China) | ? Not documented on public trust center |
| EU-US Data Privacy Framework | ✓ GitHub self-certifies compliance with EU-US DPF |
| Swiss-US Data Privacy Framework | ✓ GitHub self-certifies compliance with Swiss-US DPF |
| Global CBPR (APEC) | ? Not documented on public trust center |
| Global PRP (APEC) | ? Not documented on public trust center |
| Industry & Government | |
| HIPAA (US Healthcare) | — GitHub DPA explicitly prohibits PHI; no BAA offered |
| PCI DSS (Payment Card Industry) | ✓ GitHub maintains PCI DSS Attestation of Compliance |
| FedRAMP (US Federal) | ✓ GitHub Enterprise Cloud FedRAMP Tailored authorized per government.github.com |
| StateRAMP / TX-RAMP (US State) | ? Not documented on public trust center |
| DORA (EU Finance) | ? Not documented on public trust center |
| CJIS (US Law Enforcement) | ? Not documented on public trust center |
| FINRA (US Broker-Dealers) | ? Not documented on public trust center |
| IRAP (Australian Government) | ? Not documented on public trust center |
| Emerging & Strategic | |
| NIST CSF (Cybersecurity Framework) | ? Not explicitly documented; FedRAMP uses NIST 800-53 controls |
Data last verified: September 2026
Is this data outdated?
Spotted an error or a recent change in GitHub's posture? Submit a correction.
Submit a correction →