AI Vendor Directory · Coding assistants
Does GitHub Copilot train on your data?
No — does not train on your data by default. Vendor-stated default: no (Copilot Business/Enterprise). GitHub states its agreements with Business and Enterprise customers 'prohibit using their Copilot interaction data for model training'; prompts and suggestions are not retained for training on these tiers (covered by GitHub's Data Protection Agreement). IMPORTANT consumer-tier difference: effective 2026-04-24, Copilot Free/Pro/Pro+ (individual) interaction data — accepted/modified outputs, prompts, code context, file names, repo structure — IS used for model training by default, with a per-user opt-out toggle under Settings > Copilot > Features. Employees using personal Copilot Free/Pro accounts on company code are therefore a real leakage path; standardize on Business seats.
What is GitHub Copilot (Business)?
AI pair programmer (code completion, chat, coding agent) inside IDEs and github.com. SMBs typically buy Copilot Business seats for their engineering team.
Key facts
- Vendor: GitHub (Microsoft) — https://github.com/features/copilot
- Trains on customer data by default: no (Copilot Business/Enterprise)
- Source for the training answer: https://github.com/orgs/community/discussions/188488
- Last verified: 2026-07-29
What certifications does GitHub Copilot hold?
- SOC 1 Type 2
- SOC 2 Type 2
- ISO/IEC 27001:2022
- CSA STAR Level 2
- CSA CAIQ Level 1
- PCI DSS
Security, DPA, and subprocessor links
- Security / trust page: https://copilot.github.trust.page/
- Data processing agreement (DPA): https://github.com/customer-terms/github-data-protection-agreement
What is your EU AI Act role when you build on GitHub Copilot?
Using Copilot Business internally makes you a deployer of a third-party general-purpose AI system; GitHub/Microsoft is the provider. No Article 50 end-user transparency duty for internal coding use, but register it and govern AI-generated code under your internal AI policy.
What to record in your AI registry
- Provider: GitHub (Microsoft)
- Model type: third party api
- Data typically flowing to the vendor: source code, prompts and chat, repository metadata, usage telemetry
Sources
- https://github.com/orgs/community/discussions/188488
- https://github.com/trust-center
- https://docs.github.com/en/enterprise-cloud@latest/admin/overview/accessing-compliance-reports-for-your-enterprise
- https://copilot.github.trust.page/faq
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does GitHub Copilot train AI models on your data?
No — does not train on your data by default. Vendor-stated default: no (Copilot Business/Enterprise). GitHub states its agreements with Business and Enterprise customers 'prohibit using their Copilot interaction data for model training'; prompts and suggestions are not retained for training on these tiers (covered by GitHub's Data Protection Agreement). IMPORTANT consumer-tier difference: effective 2026-04-24, Copilot Free/Pro/Pro+ (individual) interaction data — accepted/modified outputs, prompts, code context, file names, repo structure — IS used for model training by default, with a per-user opt-out toggle under Settings > Copilot > Features. Employees using personal Copilot Free/Pro accounts on company code are therefore a real leakage path; standardize on Business seats.
What certifications does GitHub Copilot hold?
Per the vendor's published pages as of 2026-07-29: SOC 1 Type 2; SOC 2 Type 2; ISO/IEC 27001:2022; CSA STAR Level 2; CSA CAIQ Level 1; PCI DSS.
What is your EU AI Act role when you build on GitHub Copilot?
Using Copilot Business internally makes you a deployer of a third-party general-purpose AI system; GitHub/Microsoft is the provider. No Article 50 end-user transparency duty for internal coding use, but register it and govern AI-generated code under your internal AI policy.