Trusted by millions
of developers
We protect and defend the most trustworthy platform for developers everywhere to create and build software.
Explore GitHub Advanced Security Contact SalesSecure platform, secure data
We’re constantly improving our security, audit, and compliance solutions with you in mind.
Platform
We keep GitHub safe, secure, and free of spam and abuse so that this can be the platform where developers come together to create. We do this through significant investments in platform security, incident response, and anti-abuse.
Open source
Our GitHub Security Lab is a world-class security R&D team. We inspire and enable the community to secure open source at scale, so the world’s software we all depend on sits on foundations you can trust. Our ambition is to be the home where security researchers and developers can collaborate to make security easy for everyone willing to secure open source.
Customers
We help our customers' security and risk teams feel confident in their decisions to encourage developer collaboration on GitHub. We recognize that security is a shared responsibility with our customers. We are proud to partner with your security, risk, and procurement teams to provide the information needed for risk assessments and true understanding of our security and compliance posture.
Features
Ship secure applications within the GitHub flow: Stay ahead of security issues, leverage the security community’s expertise, and use open source securely.
Explore GitHub Advanced SecurityLearn more about GitHub’s Security features
Products
We embody the shift toward investments in safe and secure software design practices with our world-class security engineering program. We embed security expertise and capabilities into every phase of our Software Development Lifecycle.
Our Product Security Engineering team empowers developers to create a secure platform and products. Through developer training, the creation of components that form a secure foundation to build on, automated code analysis, in-depth threat modeling, and security code review and testing, we prevent vulnerabilities as early as possible in the development lifecycle.
Once our product is out the door, our security testing doesn’t stop. In addition to our internal Red Team, we leverage the collective expertise of the security research community through our Bug Bounty program to provide ongoing and broadly-scoped review.
Help us keep the world’s software safeWorld-renowned security program
We aim to exceed industry standards for security.
Data privacy
GitHub is committed to developer privacy and provides a high standard of privacy protection to all our developers and customers. We apply stringent individual privacy protections to all GitHub users worldwide, regardless of their country of origin or location. Read more about our Global Privacy Practices.
Read our Privacy StatementGDPR
GitHub is GDPR compliant. GDPR compliance is shown through actions, not through certifications. GitHub provides our users with the ability to access and control the information GitHub collects and processes about them. For more information, please see “How you can access and control the information we collect” in the GitHub Privacy Statement. Post Shrems II (Privacy Shield invalidation) GitHub relies on Standard Contractual Clauses (SCCs) and extends them to all of our customers.
Learn more about trans-Atlantic complianceSOC 1 and SOC 2
GitHub offers AICPA System and Organization Controls (SOC) 1 Type 2 and SOC 2 Type 2 reports with IAASB International Standards on Assurance Engagements, ISAE 2000, and ISAE 3402 for GitHub Enterprise Cloud. View the SOC 3 report for GitHub Enterprise Cloud.
Learn more about our SOC reportsFedRAMP LI-Saas Authorization to Operate (ATO)
Government users can host projects on GitHub Enterprise Cloud with the confidence that our platform meets the low impact software-as-a-service (SaaS) baseline of security standards set by our U.S. federal government partners.
Explore how GitHub works with governmentsCloud Security Alliance
GitHub is a Trusted Cloud Provider(™) with the Cloud Security Alliance (CSA). GitHub registers our Consensus Assessment Initiative Questionnaire (CAIQ) on the CSA STAR Registry.
Learn more about GitHub and CSAISO/IEC 27001:2013
GitHub's Information Security Management System (ISMS) has been certified against the ISO/IEC 27001:2013 standard. GitHub recognizes and supports that ISO/IEC 27001:2013 is the basis for many of our international customers’ programs. View the ISO/IEC 27001:2013 certification for GitHub's ISMS.
Learn more about ISO/IEC 27001:2013Safe and secure by design
Security is at the core of everything we do. When you're busy building the Next Great Thing, you don't want to worry about the security of your data, much less your development platform. That’s our job.
Latest in security
Securing the world’s software, together
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
Explore GitHub Security LabSecurity Lab bug bounty
Get rewarded for CodeQL queries that find and prevent vulnerabilities at scale in open source projects through our bounty program.
Visit our CodeQL bounty program265+ CVEs found
Ready for best-in-class enterprise security?
GitHub provides end-to-end DevSecOps, where security is embedded directly into the developer workflow—empowering you to ship secure software fast.
Explore GitHub Advanced Security