Compliance frameworks, security audits, and quality certifications this company maintains.
GitHub maintains SOC 2 Type II certification across its cloud platform, providing assurance to enterprise customers on security, availability, and confidentiality of code repositories and CI/CD pipeline data hosted on GitHub.com.
GitHub enterprise infrastructure is ISO 27001 certified, supporting enterprise and government customers with internationally recognized information security management system controls across GitHub cloud hosting.
Regulatory
FedRAMP Moderate
CertifiedGitHub Enterprise Cloud with GitHub Advanced Security has received FedRAMP Moderate authorization, enabling US federal agencies to use GitHub for software development while meeting FISMA compliance requirements.
GitHub complies with GDPR for all EU-based users and enterprise customers, providing data processing agreements, data residency options via GitHub Enterprise, and transparency into data handling practices for European organizations.
GitHub complies with the California Consumer Privacy Act (CCPA), providing California residents with rights to access, delete, and opt out of sale of personal data collected through GitHub.com and enterprise services.
GitHub Enterprise Server supports FIPS 140-2 validated cryptographic modules, enabling regulated industries and government customers to run GitHub on-premises with cryptography meeting federal security standards.
Quality
OpenSSF Best Practices
CertifiedGitHub actively supports the Open Source Security Foundation (OpenSSF) best practices framework and sponsors OpenSSF security initiatives, reflecting GitHub central role in improving open source supply chain security globally.
GitHub supports SLSA (Supply chain Levels for Software Artifacts) Level 3 provenance generation through GitHub Actions, helping software teams build tamper-evident artifact attestations for secure software supply chains.
GitHub publishes a publicly available SOC 3 report providing developers and enterprise customers high-level assurance of GitHub's security, availability, and confidentiality controls without requiring a non-disclosure agreement.
GitHub supports HIPAA compliance for healthcare development teams using GitHub Enterprise, providing Business Associate Agreements and compliant repository and CI/CD infrastructure for organizations building healthcare software.