Skip to main content

Accessing compliance reports for your organization

You can access GitHub's compliance reports, such as our SOC reports and Cloud Security Alliance CAIQ self-assessment (CSA CAIQ), for your organization.

Who can use this feature?

Organization owners can access compliance reports for the organization.

About GitHub's compliance reports

You can access GitHub's compliance reports in your organization settings.

  • SOC 1, Type 2
  • SOC 2, Type 1 (GitHub Copilot Business only)
  • SOC 2, Type 2
  • Cloud Security Alliance CAIQ self-assessment (CSA CAIQ - Level 1)
  • ISO/IEC 27001:2013 certification
  • Cloud Security Alliance STAR certification (CSA STAR - Level 2)
  • GitHub.com Services Continuity and Incident Management Plan

Accessing compliance reports for your organization

  1. In the upper-right corner of GitHub, select your profile photo, then click Your organizations.

  2. Next to the organization, click Settings.

  3. In the "Security" section of the sidebar, click Compliance.

  4. To the right of the report you want to access, click Download or View.

    Screenshot of the "Resources" section of the "Compliance" page. Next to a report, a button, labeled "Download," is outlined in orange.

Further reading