Provision record
GitHub · GitHub Acceptable Use Policies · View original document ↗

Bug bounty activities not deemed unauthorized

Low severity Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
ⓘ

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

How other platforms handle this

Public.com Medium

These choices do not apply to certain informational communications including important information and documentation relating to your account.

Microsoft Medium

We've distilled our commitment into six core values: Fairness Reliability and safety Privacy and security Transparency Accountability Inclusiveness

OpenAI Medium

We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activity

Excerpt from GitHub's Acceptable Use Policies

Provision details

Document information
Document
GitHub Acceptable Use Policies
Entity
GitHub
Tracking information
First captured by ConductAtlas
May 12, 2026
Text quoted from version
CA-V-006966, captured Sept. 16, 2026
Record ID
CA-P-060826
Document ID
CA-D-000790
Evidence Provenance
Source URL
Wayback Machine
Archived bytes SHA-256 (version CA-V-006966)
ffd0d6e02c076827157b045c1698ecb0aa7b156513fc6fbfb645520995dccad2
Analysis generated
May 20, 2026 21:06 UTC
Methodology
Evidence
✓ Excerpt found verbatim in version CA-V-006966 (checked Oct. 5, 2026)
Citation Record
Entity: GitHub
Document: GitHub Acceptable Use Policies
Record ID: CA-P-060826
Version: CA-V-006966
Captured: 2026-09-16 00:42:54 UTC
SHA-256: ffd0d6e02c076827…
URL: https://conductatlas.com/platform/github/github-acceptable-use-policies/provision/CA-P-060826/bug-bounty-activities-not-deemed-unauthorized/
Accessed: Oct. 8, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GitHub's Bug bounty activities not deemed unauthorized clause do?

The clause states: “activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activity”

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.