Certain audit documents including SOC bridge letters are available only to users who request access through the Trust Center, indicated by a lock icon on the document listing.
This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The access-restricted nature of bridge letters and detailed audit reports means enterprise customers must submit a formal access request before reviewing documents that may be critical to their compliance assessment timelines.
Removal of this generic provision suggests GitHub consolidated SOC audit document references under the new 'Gated Access to Audit Reports' provision with explicit lock-icon labeling.
View full change record →Enterprise procurement and legal teams that need audit evidence for compliance or contract purposes must submit an access request through the Trust Center portal before these restricted documents are available, which may introduce lead time into procurement timelines.
How other platforms handle this
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Access information about you consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic information transferred to another party.
If you do not want us to have this access, you should not consent to support through the remote access tool, and we will assist you through other means.
"GitHub.Enterprise.Cloud.SOC.1.Type.2.-.Bridge.Letter.01.Dec.2025.-.31.Dec.2025.pdfExcerpt from GitHub's Copilot Business Privacy Statement
(1) REGULATORY LANDSCAPE: The controlled distribution of SOC reports and bridge letters is standard practice consistent with AICPA guidance on SOC report distribution.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The access-restricted nature of bridge letters and detailed audit reports means enterprise customers must submit a formal access request before reviewing documents that may be critical to their compliance assessment timelines.
Enterprise procurement and legal teams that need audit evidence for compliance or contract purposes must submit an access request through the Trust Center portal before these restricted documents are available, which may introduce lead time into procurement timelines.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.