GitHub adds privacy and cloud security certifications
GitHub has extended its compliance portfolio with three new certifications, all assessed against its Information Security and Privacy Management System (ISPMS). The company achieved ISO/IEC 27701:2019 (PII Processor), ISO/IEC 27018:2019, and the Cloud Security Alliance's Level 2 STAR Certification. These build on the ISO/IEC 27001:2013 certification GitHub announced last year.
Scope of the ISPMS
GitHub's ISPMS is a framework covering confidentiality, integrity, availability, and privacy of information. The certification scope covers four product areas:
- GitHub.com: the integrated platform for writing and collaborating on code
- GitHub Enterprise Cloud (GHEC): the cloud-hosted code storage and management solution for organizations
- GitHub Advanced Security (GHAS): application security testing embedded in the developer workflow, running automated checks on every pull request
- GitHub Actions: CI/CD platform for automating build, test, and deployment pipelines
Within these products, the ISPMS also covers pull requests, issues, wikis, Pages, and Packages.
Privacy standards
ISO/IEC 27701:2019 extends the ISO 27001 and ISO 27002 standards with a focus on privacy information management. The PII Processor certification indicates that GitHub has implemented measures to protect personally identifiable information within its data processing systems.
ISO/IEC 27018:2019 targets protection of personal information specifically in the cloud. Based on ISO 27002, it provides implementation guidance for controls applicable to public cloud PII.
Security certification
The CSA STAR Certification uses ISO/IEC 27001 requirements as a baseline and adds requirements from the Cloud Controls Matrix (CCM). It requires a third-party assessment following standard ISO/IEC 27001 protocol and expires after three years.
Accessing the reports
Enterprise owners and organization owners can download the certification documents. Instructions are available for enterprises and for organizations. The CSA STAR certification is also listed on GitHub's STAR Registry entry.
The new certifications join GitHub's existing compliance portfolio, which includes SOC and ISAE reports, FedRAMP Tailored LiSaaS ATO, ISO 27001, and the Cloud Security Alliance CAIQ.
TISAX participation
GitHub has also begun the process of participating in the Trusted Information Security Assessment Exchange (TISAX), currently in the audit provider selection stage. TISAX is administered by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). The program is intended to help GitHub better serve enterprise customers in the automotive industry. A TISAX entry on the GitHub public roadmap is forthcoming.



