This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
How other platforms handle this
These choices do not apply to certain informational communications including important information and documentation relating to your account.
We've distilled our commitment into six core values: Fairness Reliability and safety Privacy and security Transparency Accountability Inclusiveness
We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction.
"activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activityExcerpt from GitHub's Acceptable Use Policies
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause states: “activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activity”
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.