Executive Summary
AI-generated analysis for GitHub
GitHub (github.com) is a widely adopted software development platform owned by Microsoft, assessed here as a SaaS tool with medium data access. The rule engine has assigned a Tier 3 (Moderate Risk) rating, driven primarily by a documented supply-chain security incident affecting downstream organizations and an AI data training policy that defaults to opt-out rather than opt-in for certain product tiers. GitHub presents a strong overall security posture across most measurable dimensions:
Key Findings
- FedRAMP LI-SaaS authorization has been independently verified via the FedRAMP Marketplace, effective March 2023
- SOC 2 Type II compliance is claimed on the vendor's trust page and SOC 1 Type II is also documented — full reports should be requested directly
- TLS 1.3 is enforced with no weak protocols, and the HTTP security posture earned an A+ grade from HTTP security scanner
- A mandatory platform-wide 2FA/MFA requirement has been in place since March 2023
- The domain carries an 18.5-year registration history, a clean threat intelligence profile, and a 0/100 IP abuse confidence score
- 23 subprocessors are publicly listed with no sanctions matches detected Two areas require attention before this vendor is approved for in-scope use. First, adverse media reporting indicates a supply-chain attack originating from a GitHub breach in 2025 affected over 700 downstream organizations — the scope and remediation status of this incident should be confirmed with the vendor. Second, GitHub's AI data usage policy contains tiered training commitments: Copilot Business and Enterprise customers are explicitly excluded from AI training, but free and consumer-tier users are subject to opt-out training starting April 24, 2026. Organizations storing proprietary code should confirm their plan tier and verify opt-out configuration. Additionally, SSH (port 22) is publicly exposed, and the TLS certificate on the primary domain expires in 47 days. Overall, GitHub is a mature, compliance-rich platform with a well-documented security program, but the unresolved supply-chain incident and AI training policy ambiguity justify the Tier 3 rating and a conditional approval posture pending documented remediation and policy confirmation.
Independence Statement
All evidence in this assessment was independently sourced from external data providers, public registries, and open-source intelligence without vendor participation or self-reporting.