Vannus / Catalog / GitHub Copilot

GitHub Copilot

Vannus records that this vendor routes across several model providers — not captured by one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with GitHub, Inc. (United States) — within reach of US legal process.
Controlled by Microsoft Corporation (United States), per the vendor's own LEI filing, entity-supplied [2026-09-13].
assets.ctfassets.net · read 2026-09-16
read from a master agreement · inferred from the address, not the heading

AI pair programmer that suggests code completions and entire functions in your editor

coding, productivity, developer tools
What the vendor's own documentation says
These models are hosted by Amazon Web Services, Anthropic PBC, and Google Cloud Platform.
docs.github.com ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
US corporate controlYes — a US parent or US contracting entity is on the public record · clause re-checked 17 Sep 2026
Contracting entityGitHub, Inc. — the sole contracting entity worldwide for customers who buy directly from GitHub. The General Terms Definitions state simply: "GitHub" means GitHub, Inc. There is NO regional entity split: EU/EEA/Swiss customers also contract with GitHub, Inc., a US company and a wholly owned subsidiary of Microsoft Corporation. (The only alternative path is buying Copilot through a Microsoft volume licensing agreement, in which case the Microsoft agreement and its own contracting entity govern instead.)
Governing lawTwo-branch region split on LAW ONLY, not on entity. Default: laws of the State of California and federal laws of the United States, with exclusive venue in the federal or state courts located in the Northern District of California. Carve-out: if Customer's principal office is within the European Union, European Economic Area, or Switzerland, the Agreement is instead governed by the laws of Ireland, with exclusive venue in the courts located in Dublin. Both branches contract with the same US entity, GitHub, Inc. The 1980 UN Convention on Contracts for the International Sale of Goods is excluded. (The older GitHub Corporate Terms of Service, a legacy base agreement still in force for some customers, uses an equivalent but differently-drawn split: Americas -> California law / N.D. Cal.; outside the Americas -> laws of Ireland / Dublin courts.)
Trains on your dataYes, unless you opt out — on the vendor's default plan
On a paid or enterprise planDoes not train on your data — no retention position stated

Applies to: Copilot Business, Copilot Enterprise (contrasted with Copilot Free, Pro, Pro+)

From the vendor product page FAQ / trust section (github.com/features/copilot): “No. GitHub does not use either Copilot Business or Enterprise data to train its models.” github.com ↗

Training and retention posture varies by plan. The default-plan row above describes the vendor’s free or standard tier; the paid-plan row is quoted from the document linked beside it. A negotiated contract can override either. Check your own agreement before relying on this.

This is a separate question from the grade above. The grade measures resilience — whether the tool endures and whether you could leave it. This describes who controls the vendor. A tool can score modestly on one and strongly on the other, and many do.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Origin
United States

The vendor's published or catalog-recorded posture — the concrete facts this grade is built from. A full audit verifies each against the vendor's current documentation.

Compliance the vendor states
SOC2GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this grade is set

Vannus publishes a nine-dimension trust framework — data sovereignty, training privacy, compliance posture, operational resilience, exit portability, and more. The heaviest criterion asks whether the tool builds its own AI or resells someone else's model; where the vendor discloses it, the grade cites the vendor's own documentation. No paid placements — scoring is walled off from affiliate revenue. See the methodology →

Related tools we grade
Visit GitHub Copilot ↗ Grade your whole stack →