Provision record
GitHub · GitHub Acceptable Use Policies · View original document ↗

Bug bounty activities not deemed unauthorized

Low severity Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track GitHub and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

How other platforms handle this

Skillshare Medium

by blocking, disabling, or managing any or all cookies, you may not have access to certain features or offerings of the Services.

Baseten Medium

These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.

Cerebras Medium

We do not respond to browser-initiated Do Not Track signals.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activity

Excerpt from GitHub's Acceptable Use Policies

Provision details

Document information
Document
GitHub Acceptable Use Policies
Entity
GitHub
Document last updated
May 12, 2026
Tracking information
First tracked
May 20, 2026
Last verified
May 20, 2026
Record ID
CA-P-060826
Document ID
CA-D-00790
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
4cb1cc8f63e15186f39023d0124a0552f90d900ee77625b9086bf67218c19c3e
Analysis generated
May 20, 2026 21:06 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Acceptable Use Policies
Record ID: CA-P-060826
Captured: 2026-05-20 21:06:09 UTC
SHA-256: 4cb1cc8f63e15186…
URL: https://conductatlas.com/platform/github/github-acceptable-use-policies/provision/CA-P-060826/bug-bounty-activities-not-deemed-unauthorized/
Accessed: Aug. 2, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does GitHub's Bug bounty activities not deemed unauthorized clause do?

The clause states: “activities permitted under bug bounty programs, such as the GitHub Bug Bounty program, are not considered "unauthorized," but must only affect the organization whose bug bounty program authorized the activity”

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.