This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause defines GitHub's audit certification scope and reporting availability for Enterprise customers, establishing the mechanism through which customers can obtain third-party attestations of GitHub's control environment and security practices during the specified audit period.
Enterprise Cloud customers operating during the bridge period can request access to GitHub's SOC 1 Type 2 audit reports, which document GitHub's internal controls over security, availability, and data protection. This provision establishes the availability and timing of this documentation but does not specify access restrictions or conditions beyond the date range.
Cross-platform context
See how other platforms handle Access-Gated Audit Reports and similar clauses.
Compare across platforms →Monitoring
GitHub has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
"GitHub.Enterprise.Cloud.SOC.1.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdf— Excerpt from GitHub's GitHub Copilot Business Privacy Statement
Professional Governance Intelligence
Need to monitor specific governance provisions?
Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause defines GitHub's audit certification scope and reporting availability for Enterprise customers, establishing the mechanism through which customers can obtain third-party attestations of GitHub's control environment and security practices during the specified audit period.
Enterprise Cloud customers operating during the bridge period can request access to GitHub's SOC 1 Type 2 audit reports, which document GitHub's internal controls over security, availability, and data protection. This provision establishes the availability and timing of this documentation but does not specify access restrictions or conditions beyond the date range.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.