{
  "slug": "github",
  "category": "code-hosting",
  "name": "GitHub",
  "description": "Git hosting service owned by Microsoft, with pull requests, issues, Actions CI/CD, package hosting, Pages static sites and Copilot AI features.",
  "website": "https://github.com",
  "license": null,
  "platforms": [
    "web",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 100,
  "summary": "GitHub scores 50 out of 100 (grade D) on the code hosting criteria. It meets 4 of 8 criteria: transparency report, tells users about requests, TLS configuration and security headers. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/code-hosting/github/",
  "markdown": "https://privacyratings.com/code-hosting/github/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source. Some tools, such as GitHub Desktop and GitHub CLI, are open source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
      "note": "The privacy statement allows third-party cookies for interest-based advertising, and the Exodus report finds Google Firebase Analytics and Crashlytics in the Android app."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
      "note": "Funded by subscriptions, but the privacy statement says third-party cookies may gather data for interest-based advertising."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization",
      "note": "SOC reports and ISO/IEC 27001 certification are only available to organization owners in account settings."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://transparencycenter.github.com/",
      "note": "Publishes a transparency report with counts of requests for user information, disclosures and takedowns, with data in the github/transparency repository."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://docs.github.com/en/site-policy/other-site-policies/guidelines-for-legal-requests-of-user-data",
      "note": "Policy is to notify affected users about requests for their account information unless prohibited by law or court order."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=github.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=github.com",
      "note": "Grade A+ (115/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:06:27.169Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}