Platform is certified at the Low baseline; Copilot is not named on the record
GitHub Enterprise Cloud's FedRAMP record is Class B (Low), below the Moderate baseline DFARS 252.204-7012 asks of an external cloud service provider — and the word Copilot does not appear anywhere on that record.
Is GitHub Copilot (Business and Enterprise) safe for CUI?
by GitHub
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“GitHub Enterprise Cloud Package ID FR1812058188 ... Type Rev5 Path Agency Class Class B (Low)”
FedRAMP Marketplace — GitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
FedRAMP
Platform certified at Class B (Low)
DoD Impact Level
Not established
Deployment pattern
Commercial multi-tenant SaaS
Overview
GitHub Copilot sits in the developer workflow, which is exactly where controlled technical information tends to live in an engineering-heavy contractor. The authorization picture is unusually clear-cut on one point: the platform holds a Low-baseline FedRAMP certification, and Copilot is not itemised on that record.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Not established. We did not establish, from a primary source, where Copilot inference is processed for a given Business or Enterprise tenant. GitHub documents a data-residency capability for GitHub Enterprise Cloud; whether it binds Copilot inference for your tenant is a question for GitHub in writing.
Model training and retention
GitHub states it does not use Copilot Business or Enterprise data to train its models. As elsewhere, this speaks to data use and not to which authorization boundary the code and prompts sit in.
Primary source
“GitHub does not use either Copilot Business or Enterprise data to train its models.”
GitHub — GitHub Copilot plans — data use · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
The FedRAMP record for GitHub Enterprise Cloud is a Rev5, Agency-path certification at Class B (Low). Two things follow. Low is below the FedRAMP Moderate baseline DFARS 252.204-7012 requires of an external cloud service provider handling covered defense information. And the record carries no mention of Copilot at all — a platform certification is not a certification of every service on the platform.
Primary source
“GitHub Enterprise Cloud Package ID FR1812058188 ... Type Rev5 Path Agency Class Class B (Low)”
FedRAMP Marketplace — GitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27
DoD Impact Level
Not established. No DoD Impact Level authorization was established for GitHub or GitHub Copilot from any primary source we read. Verify with GitHub.
Vendor's own position on CUI
Not established. We found no GitHub statement establishing a position on CUI, DFARS 252.204-7012 or ITAR for Copilot. Absence of a statement is not a prohibition — it means the question is unanswered and you should put it to GitHub in writing.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Source code is often the quiet CUI problem: controlled technical information and export-controlled designs end up in repositories that were never scoped as a CUI system. Decide first whether the repository itself is in your CUI boundary. If it is, a Low-baseline external platform is the wrong place for it regardless of Copilot, and the fix is repository placement, not an AI setting. If it is not, keep it that way with pre-commit scanning and repository-level controls, and keep the Copilot decision downstream of the repository decision.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- FedRAMP Marketplace — GitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27
- Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
- GitHub — GitHub Copilot plans — data use · read 2026-07-27
Authorization records move and this page does not. Confirm the GitHub package record on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
GitHub is FedRAMP authorized — does that cover Copilot?
The GitHub Enterprise Cloud record is a Class B (Low) certification, and the word Copilot appears nowhere on it. Platform-level authorization does not automatically extend to a service running on the platform, and Low does not meet the FedRAMP Moderate equivalency DFARS 252.204-7012 asks for.
Is source code CUI?
Sometimes — controlled technical information is a CUI category, and export-controlled designs and technical data packages routinely live in repositories. Whether a given repository is in your CUI boundary is a scoping decision to make deliberately rather than discover during an assessment.
Is there a government version of GitHub Copilot?
We did not establish one from a primary source. If you need AI assistance against CUI-bearing code, the patterns that do have an authorization story are a model running inside an authorized government cloud boundary, or a self-hosted model inside your own enclave.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This GitHub Copilot (Business and Enterprise) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review