GitHub has SOC for Service Organizations reports
Blog post from GitHub
GitHub has announced achieving significant security compliance milestones by obtaining AICPA Service Organization Controls (SOC) 2 Type 1 and SOC 1 Type 1 compliance for its Business Cloud, along with ISAE 3000 and ISAE 3402 for international customers. These achievements reflect GitHub's commitment to maintaining high security standards and providing assurance to its customers that their data is secure. SOC reports, widely regarded as the gold standard for security compliance in the US, require strict adherence to information security policies, and GitHub's compliance affirms its dedication to protecting customer data. The company also plans to issue SOC 1 and SOC 2 Type 2 reports biannually to further enhance its security framework. GitHub's security measures encompass various operational practices, such as access management, data protection, and incident response, demonstrating the effectiveness of its controls.