AI Tool Risk Directory ← All 26 tools Verdict assessed 29 July 2026

Is GitHub Copilot safe for work? Verdict: Limited

Limited

GitHub Copilot can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. Business/Enterprise plans carry no-training terms and zero-retention agreements with the model providers — but GitHub names exceptions to those agreements on the same page, and code context still leaves the editor, so repos with secrets or client code need explicit written rules. The policy questions are IP hygiene (public-code matching, license contamination) and secrets in code context — not just data training. GitHub states the models themselves were trained on publicly available source code.

This verdict reflects GitHub (Microsoft)’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.

GitHub Copilot at a glance

VendorGitHub (Microsoft)
CategoryCode assistant
Our tier verdictLimited (assessed 29 July 2026) — Business/Enterprise plans carry no-training terms and zero-retention agreements with the model providers — but GitHub names exceptions to those agreements on the same page, and code context still leaves the editor, so repos with secrets or client code need explicit written rules. source
Trains on your data?Depends on plan / settings
Depends on the plan. GitHub states it "does not use Copilot Business or Copilot Enterprise customer data to train AI models". For individual subscribers — it names Copilot Free, Pro, Pro+ and Max — it states it "may use Copilot interaction data, including prompts (inputs), suggestions (outputs), and code snippets generated during Copilot sessions to train and improve AI models", subject to an opt-out the individual sets. That opt-out belonging to the employee rather than to you is a second reason to ban personal-account use for work code. source
Data retentionZero-retention by contract, with exceptions GitHub names itself — read them before quoting the headline. GitHub states it maintains a zero data retention agreement with OpenAI, and one with Anthropic "for generally available Anthropic features in GitHub Copilot" while "Some Anthropic features in beta or public preview—including tool search via the Messages API—are not covered by this agreement". It also warns that when Claude Fable 5 is used, "Anthropic retains data, including prompts and outputs, to operate safety classifiers that detect harmful use", and that enterprise and business admins must enable that model for their organisation. The other providers are worded differently again: Amazon Bedrock "doesn’t store or log your prompts and completions", Google "commits to not training on GitHub data", and xAI runs Grok 4.5 under a zero-data-retention API policy. GitHub additionally uses prompt caching with Anthropic, Bedrock and Google Cloud. The accurate summary is per-provider retention contracted down to zero for generally available features, not a blanket "nothing is kept". source
Admin controlsLicence and policy management on the organisation plans, an optional duplication-detection filter an enterprise administrator can enable to suppress suggestions matching public code on GitHub, audit logs, and IP indemnity on Business and Enterprise. source
Compliance certificationsGitHub publishes trust and compliance material separately; we did not verify its current certification list from a primary document on this check date.
HIPAA / BAAN/A — not a PHI system — Not applicable — GitHub does not market Copilot as a system for processing protected health information, and we found no published BAA for it.

Does GitHub Copilot train on your data?

Depends on the plan. GitHub states it "does not use Copilot Business or Copilot Enterprise customer data to train AI models". For individual subscribers — it names Copilot Free, Pro, Pro+ and Max — it states it "may use Copilot interaction data, including prompts (inputs), suggestions (outputs), and code snippets generated during Copilot sessions to train and improve AI models", subject to an opt-out the individual sets. That opt-out belonging to the employee rather than to you is a second reason to ban personal-account use for work code.

Retention: Zero-retention by contract, with exceptions GitHub names itself — read them before quoting the headline. GitHub states it maintains a zero data retention agreement with OpenAI, and one with Anthropic "for generally available Anthropic features in GitHub Copilot" while "Some Anthropic features in beta or public preview—including tool search via the Messages API—are not covered by this agreement". It also warns that when Claude Fable 5 is used, "Anthropic retains data, including prompts and outputs, to operate safety classifiers that detect harmful use", and that enterprise and business admins must enable that model for their organisation. The other providers are worded differently again: Amazon Bedrock "doesn’t store or log your prompts and completions", Google "commits to not training on GitHub data", and xAI runs Grok 4.5 under a zero-data-retention API policy. GitHub additionally uses prompt caching with Anthropic, Bedrock and Google Cloud. The accurate summary is per-provider retention contracted down to zero for generally available features, not a blanket "nothing is kept".

Is GitHub Copilot HIPAA compliant?

Not applicable — GitHub does not market Copilot as a system for processing protected health information, and we found no published BAA for it. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Comparing vendors on this specifically? See BAA status for all 26 tools →

Is GitHub Copilot SOC 2 certified?

Not verified from a primary document on this check date. GitHub publishes trust and compliance material separately; we did not verify its current certification list from a primary document on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how GitHub Copilot runs its controls, not what your agreement with them permits.

Industry risk notes

Healthcare

HIPAA is the gate: Not applicable — GitHub does not market Copilot as a system for processing protected health information, and we found no published BAA for it. Until a BAA is confirmed in writing, treat GitHub Copilot as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.

Financial services

For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through GitHub Copilot be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? Licence and policy management on the organisation plans, an optional duplication-detection filter an enterprise administrator can enable to suppress suggestions matching public code on GitHub, audit logs, and IP indemnity on Business and Enterprise.

Legal & professional services

The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Because training and retention on GitHub Copilot depend on account type and settings, assume client matter data is off-limits unless your firm controls the account and has verified the terms.

Primary sources

Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.

Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.

Why the tier verdict is "generic": Limited is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies GitHub Copilot and 25 other tools specifically for your industry, company size, and the data your team handles.

And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.

Frequently asked questions

Is GitHub Copilot safe for work?

GitHub Copilot can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. Business/Enterprise plans carry no-training terms and zero-retention agreements with the model providers — but GitHub names exceptions to those agreements on the same page, and code context still leaves the editor, so repos with secrets or client code need explicit written rules. The policy questions are IP hygiene (public-code matching, license contamination) and secrets in code context — not just data training. GitHub states the models themselves were trained on publicly available source code.

Does GitHub Copilot train on your data?

Depends on the plan. GitHub states it "does not use Copilot Business or Copilot Enterprise customer data to train AI models". For individual subscribers — it names Copilot Free, Pro, Pro+ and Max — it states it "may use Copilot interaction data, including prompts (inputs), suggestions (outputs), and code snippets generated during Copilot sessions to train and improve AI models", subject to an opt-out the individual sets. That opt-out belonging to the employee rather than to you is a second reason to ban personal-account use for work code.

Is GitHub Copilot HIPAA compliant?

Not applicable — GitHub does not market Copilot as a system for processing protected health information, and we found no published BAA for it. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Is GitHub Copilot SOC 2 certified?

Not verified from a primary document on this check date. GitHub publishes trust and compliance material separately; we did not verify its current certification list from a primary document on this check date. Ask for the current SOC 2 report under NDA before you rely on it. A certification is also not a contract: it describes how GitHub Copilot runs its controls, not what your agreement with them permits.

What tier should GitHub Copilot be in an AI acceptable use policy?

We classify GitHub Copilot as Limited for a typical 50–500 person company, assessed 29 July 2026. Business/Enterprise plans carry no-training terms and zero-retention agreements with the model providers — but GitHub names exceptions to those agreements on the same page, and code context still leaves the editor, so repos with secrets or client code need explicit written rules. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.

New to the topic? Start with what shadow AI is — definition, examples and risks, then measure your own exposure with the shadow AI scorer.

Your team is using GitHub Copilot. Does your AI policy cover it?

Most policies name a handful of tools and go stale the month after they are written. Two ways to find out where yours stands: check an existing policy for gaps in 30 seconds, or generate a policy that classifies GitHub Copilot by name — free preview, no account. Starting from scratch? The free 14-section AI acceptable use policy template is the document itself, ungated.

Get the full policy kit

$79 one-time

A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies GitHub Copilot and 25 other tools for your company, industry, and data. Generated in about 10 minutes.

Generate my policy kit →

Keep it current with Monitor

$149/mo

We re-check vendor terms monthly and alert you when GitHub Copilot’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.

See Monitor plan →

Work out where GitHub Copilot leaves you exposed

Compare with productivity-suite and business-platform AI

Already have an AI policy? Check it for gaps in 30 seconds →