Vannus / Catalog / GitHub Actions

GitHub Actions A Sovereign

Graded A on resilience. In Vannus's assessment it has not disclosed which model it runs — builds its own AI or is not captured by any single model provider.

automation, devops, ci/cd
Model provenance

Not disclosed. GitHub Actions does not publish which model it runs, so this criterion is excluded and the grade rests on what we could verify. We say so rather than guess.

Compliance signals on file
SOC2GDPRFedRAMP
How this grade is set

Vannus grades GitHub Actions against nine dimensions of trust — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Visit GitHub Actions ↗ Grade your whole stack →