GitHub · GitHub Copilot Business Privacy Statement · View original document ↗

TISAX Certification Disclosure

Low severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity GitHub recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for GitHub Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

GitHub Copilot holds a TISAX certification, which is an information security assessment standard used in the automotive industry to evaluate suppliers and service providers.

This analysis describes what GitHub's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

TISAX certification indicates that GitHub Copilot has been assessed against the VDA ISA (Verband der Automobilindustrie Information Security Assessment) standard, which is required by many automotive manufacturers for their supply chain technology vendors.

Interpretive note: TISAX results are not publicly disclosed; the Trust Center lists the certification but the specific assessment level, scope, and ENX result identifier are not visible on this page, requiring direct verification through the ENX portal.

Consumer impact (what this means for users)

Enterprise customers in the automotive sector or automotive supply chain who require TISAX-certified vendors can reference this certification when evaluating GitHub Copilot for use in automotive-related development workflows.

Cross-platform context

See how other platforms handle TISAX Certification Disclosure and similar clauses.

Compare across platforms →

Monitoring

GitHub has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
TISAX

— Excerpt from GitHub's GitHub Copilot Business Privacy Statement

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: TISAX is administered by ENX Association and is based on the VDA ISA standard. It is not a government regulation but is contractually required by many major automotive OEMs (original equipment manufacturers) in their supplier agreements. It maps to ISO 27001 and is relevant to organizations subject to automotive sector data protection and security requirements in Germany and the broader EU automotive supply chain. (2) GOVERNANCE EXPOSURE: Low for non-automotive organizations. Medium for automotive sector enterprises where TISAX is contractually mandated by OEM customers. The governance consideration is confirming the specific TISAX assessment level and scope applicable to GitHub Copilot. (3) JURISDICTION FLAGS: Primarily relevant to Germany-based enterprises and EU automotive supply chain participants. TISAX results are shared through the ENX portal on a controlled basis; unlike ISO certifications, TISAX results are not publicly disclosed and must be shared directly between assessed companies and their customers. (4) CONTRACT AND VENDOR IMPLICATIONS: Automotive sector procurement teams should request the TISAX result identifier from GitHub to verify the assessment level, scope, and validity period through the ENX portal. This is distinct from other certifications listed on the Trust Center, as TISAX results require ENX portal access to verify. (5) COMPLIANCE CONSIDERATIONS: Compliance teams in the automotive sector should confirm that the TISAX assessment scope covers the specific GitHub Copilot workflows and data types used in their automotive development environment. They should also verify the assessment level matches their OEM customer contractual requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Provision details

Document information
Document
GitHub Copilot Business Privacy Statement
Entity
GitHub
Document last updated
May 11, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 12, 2026
Record ID
CA-P-011451
Document ID
CA-D-00775
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
03df476a478d1fd1c273db6268eecab506201949e8baa23fd4086c19e11c3b81
Analysis generated
May 11, 2026 12:16 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: GitHub
Document: GitHub Copilot Business Privacy Statement
Record ID: CA-P-011451
Captured: 2026-05-11 12:16:26 UTC
SHA-256: 03df476a478d1fd1…
URL: https://conductatlas.com/platform/github/github-copilot-business-privacy-statement/tisax-certification-disclosure/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does GitHub's TISAX Certification Disclosure clause do?

TISAX certification indicates that GitHub Copilot has been assessed against the VDA ISA (Verband der Automobilindustrie Information Security Assessment) standard, which is required by many automotive manufacturers for their supply chain technology vendors.

How does this clause affect you?

Enterprise customers in the automotive sector or automotive supply chain who require TISAX-certified vendors can reference this certification when evaluating GitHub Copilot for use in automotive-related development workflows.

Is ConductAtlas affiliated with GitHub?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by GitHub.