This is a print-friendly report. Click Print and choose “Save as PDF” in the destination dropdown to download.

SaaSGuard Risk Report

GitHub

github.com

Generated May 4, 2026

Grade C

Score: 67 / 100

Executive summary

We analyzed GitHub’s Terms of Service across 8 risk dimensions and found 7 flagged clauses across 5 categories. 1 material change detected in the recent crawl history.

Recent material changes

  • 2/28/2024 · severity 5

    GitHub Copilot Business reversed its explicit no-training promise and began defaulting to opt-in code collection for AI training. Organizations must now actively find and disable a settings toggle to prevent their proprietary code from entering training pipelines.

    Enterprises using Copilot Business under the assumption their code wasn't being harvested — especially those with export-controlled, regulated, or trade-secret-protected codebases.

Flagged clauses by category

AI training on your data (1)

  • Severity 4 · material

    By using automated means to access, collect, or otherwise use (“Access”) any publicly accessible Content from the Service for the purpose of developing or training any commercially available artificial intelligence model, machine learning system, or similar technology (a "Commercial AI System"), you hereby waive any and all policies, terms, conditions, or contractual provisions governing products, services, websites or datasets you own or operate that would otherwise prohibit, restrict, or place conditions upon GitHub's Access to any publicly accessible data, information or content associated with your products or services, including for the purpose of developing or training any Commercial AI System.

    GitHub accesses publicly available content from your services to develop or train its Commercial AI Systems, and you waive any terms that would otherwise prohibit this.

    Your own terms of service are overridden, allowing GitHub to use your public data for AI training without restriction.

Termination friction (1)

  • Severity 2 · minor

    GitHub has the right to suspend or terminate your access to all or any part of the Website at any time, with or without cause, with or without notice, effective immediately.

    GitHub can suspend or terminate your access to the service at any time, for any reason, with or without notice.

    Your access to the service can be revoked immediately and without explanation.

Liability caps (1)

  • Severity 4 · material

    You understand and agree that we will not be liable to you or any third party for any loss of profits, use, goodwill, or data, or for any incidental, indirect, special, consequential or exemplary damages, however arising, that result from the use, disclosure, or display of your User-Generated Content; your use or inability to use the Service; any modification, price change, suspension or discontinuance of the Service; the Service generally or the software or systems that make the Service available; unauthorized access to or alterations of your transmissions or data; statements or conduct of any third party on the Service; any other user interactions that you input or receive through your use of the Service; or any other matter relating to the Service.

    GitHub is not liable for any losses or damages arising from your use of the service, including lost profits, data, or goodwill, or from any modification, suspension, or discontinuance of the service.

    You cannot hold GitHub responsible for any financial or operational harm you experience due to their service.

Indemnification (1)

  • Severity 3 · notable

    You agree to indemnify us, defend us, and hold us harmless from and against any and all claims, liabilities, and expenses, including attorneys’ fees, arising out of your use of the Website and the Service, including but not limited to your violation of this Agreement, provided that GitHub (1) promptly gives you written notice of the claim, demand, suit or proceeding; (2) gives you sole control of the defense and settlement of the claim, demand, suit or proceeding (provided that you may not settle any claim, demand, suit or proceeding unless the settlement unconditionally releases GitHub of all liability); and (3) provides to you all reasonable assistance, at your expense.

    You agree to defend and hold GitHub harmless from any claims arising from your use of the service or violation of the agreement.

    You must cover GitHub's legal costs and damages if your actions lead to a lawsuit against them.

Right to silently change terms (3)

  • Severity 3 · notable

    We will notify our Users of material changes to this Agreement, such as price increases, at least 30 days prior to the change taking effect by posting a notice on our Website or sending email to the primary email address specified in your GitHub account.

    GitHub will inform users about significant changes, like price increases, at least 30 days before they happen by posting a notice or sending an email.

    You will receive advance notice of major changes, giving you time to decide if you want to continue using the service.

  • Severity 3 · notable

    Customer's continued use of the Service after those 30 days constitutes agreement to those revisions of this Agreement.

    If you continue to use the service after 30 days, you agree to the revised terms.

    Your continued use of the service after the notice period implies your acceptance of any new terms.

  • Severity 3 · notable

    We reserve the right, at our sole discretion, to amend these Terms of Service at any time and will update these Terms of Service in the event of any such amendments.

    GitHub reserves the right to change the Terms of Service at its discretion and will update them when changes occur.

    GitHub can unilaterally change the rules governing your use of their service at any time.

Methodology

SaaSGuard uses an automated pipeline: a daily Playwright crawler captures each vendor’s public Terms of Service, Privacy Policy, and DPA. Google’s Gemini 2.5 Flash classifies each clause into one of 8 risk categories with a severity score (1–5). Clauses are cross-referenced against a curated database of real lawsuits and FTC actions via embedding-based similarity matching. Grades are computed from per-category max severity; full source code is available on request.

Built for educational and informational purposes. Not legal advice. Always have your own counsel review SaaS contracts before signing.

View live page →