AI Vendor Directory · Coding assistants
Does GitHub Copilot train on your data?
No — does not train on your data by default. Vendor-stated default: no (Copilot Business/Enterprise). GitHub states its agreements with Business and Enterprise customers 'prohibit using their Copilot interaction data for model training'; prompts and suggestions are not retained for training on these tiers (covered by GitHub's Data Protection Agreement). IMPORTANT consumer-tier difference: effective 2026-04-24, Copilot Free/Pro/Pro+ (individual) interaction data — accepted/modified outputs, prompts, code context, file names, repo structure — IS used for model training by default, with a per-user opt-out toggle under Settings > Copilot > Features. Employees using personal Copilot Free/Pro accounts on company code are therefore a real leakage path; standardize on Business seats.
By the Shieldra Compliance Team · Last updated 2026-07-29
What is GitHub Copilot (Business)?
AI pair programmer (code completion, chat, coding agent) inside IDEs and github.com. SMBs typically buy Copilot Business seats for their engineering team.
Key facts
- Vendor: GitHub (Microsoft) — https://github.com/features/copilot
- Trains on customer data by default: no (Copilot Business/Enterprise)
- Source for the training answer: https://github.com/orgs/community/discussions/188488
- Last verified: 2026-07-29
What certifications does GitHub Copilot hold?
- SOC 1 Type 2
- SOC 2 Type 2
- ISO/IEC 27001:2022
- CSA STAR Level 2
- CSA CAIQ Level 1
- PCI DSS
Security, DPA, and subprocessor links
- Security / trust page: https://copilot.github.trust.page/
- Data processing agreement (DPA): https://github.com/customer-terms/github-data-protection-agreement
What is your EU AI Act role when you build on GitHub Copilot?
Using Copilot Business internally makes you a deployer of a third-party general-purpose AI system; GitHub/Microsoft is the provider. No Article 50 end-user transparency duty for internal coding use, but register it and govern AI-generated code under your internal AI policy.
What to record in your AI registry
- Provider: GitHub (Microsoft)
- Model type: third party api
- Data typically flowing to the vendor: source code, prompts and chat, repository metadata, usage telemetry
Sources
- https://github.com/orgs/community/discussions/188488
- https://github.com/trust-center
- https://docs.github.com/en/enterprise-cloud@latest/admin/overview/accessing-compliance-reports-for-your-enterprise
- https://copilot.github.trust.page/faq
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does GitHub Copilot train AI models on your data?
No — does not train on your data by default. Vendor-stated default: no (Copilot Business/Enterprise). GitHub states its agreements with Business and Enterprise customers 'prohibit using their Copilot interaction data for model training'; prompts and suggestions are not retained for training on these tiers (covered by GitHub's Data Protection Agreement). IMPORTANT consumer-tier difference: effective 2026-04-24, Copilot Free/Pro/Pro+ (individual) interaction data — accepted/modified outputs, prompts, code context, file names, repo structure — IS used for model training by default, with a per-user opt-out toggle under Settings > Copilot > Features. Employees using personal Copilot Free/Pro accounts on company code are therefore a real leakage path; standardize on Business seats.
What certifications does GitHub Copilot hold?
Per the vendor's published pages as of 2026-07-29: SOC 1 Type 2; SOC 2 Type 2; ISO/IEC 27001:2022; CSA STAR Level 2; CSA CAIQ Level 1; PCI DSS.
What is your EU AI Act role when you build on GitHub Copilot?
Using Copilot Business internally makes you a deployer of a third-party general-purpose AI system; GitHub/Microsoft is the provider. No Article 50 end-user transparency duty for internal coding use, but register it and govern AI-generated code under your internal AI policy.