GitHub, Inc.
United States · owned by Microsoft Corporation (United States) · github.com · 65 vendors
GitHub is a developer platform that allows developers to create, store, manage and share their code. It uses Git, a version control system, to track changes in source code during software development.
Resilience scores
- Digital Sovereignty: 86
- Digital Resilience: 6
- Financial Resilience: 9
Disruption prediction
GitHub, Inc. has a 100% probability of disruption in the next 6 months.
Active disruption (last checked 2026-09-18 14:55 UTC): Degradation with Gemini 3.8 Flash
37 of GitHub, Inc.'s 65 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 62 more
Services catalogue
21 services in catalogue across 8 categories; runs on 65 sub-vendors.
- Copilot
- Code Review
- Web Font Loader
Insights
Last updated 2026-07-17 · revision 29
65 direct vendors, 421 subvendors
Direct vendors by controlling owner country (sample)
- Switzerland: 1
- United States: 56
- Australia: 1
Subvendors by controlling owner country (sample)
- Netherlands: 6
- Denmark: 6
- South Korea: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
GitHub demonstrates high migration readiness. A key strength is its highly modern and cloud-native internal tech stack, utilizing Kubernetes, Docker, and Azure as its primary cloud provider. This foundation, along with modern languages and frameworks (Go, Node.js, React, TypeScript), indicates strong architectural flexibility for agile development and potential migrations. The company's robust financial growth (projected $2B revenue in 2024) provides ample resources to fund significant migration or re-platforming initiatives. However, several challenges exist. The complex global regulatory environment, particularly strong GDPR compliance and extensive data residency requirements across 15+ countries (including specific localization options for Enterprise customers), would add significant complexity and cost to any large-scale migration involving data movement or re-architecture. The 'Unknown' status for SOC2 and ISO 27001 certifications could pose a hurdle for migrations, especially if target environments or new service integrations require these compliance benchmarks. While the 'Total Vendors: 0' is contradictory and likely incomplete, the reliance on Azure as the 'primary cloud' suggests a degree of cloud vendor lock-in, which, while common, is a factor in migration complexity. The lack of a clear vendor count prevents a detailed assessment of vendor-specific lock-in risks beyond the primary cloud provider.
Compliance
10 in-scope frameworks identified; showing 3.
NIST Cybersecurity Framework — Compliant
GitHub explicitly references alignment with the NIST AI Risk Management Framework and follows NIST standards as part of its FedRAMP authorization (NIST SP 800-53). GitHub's security program is structured around NIST CSF principles (Identify, Protect, Detect, Respond, Recover). Risk is Low because NIST CSF is a voluntary framework in the US (not a mandatory regulation), and GitHub's existing certifications (ISO 27001, SOC 2, FedRAMP) demonstrate alignment with NIST CSF principles.
Evidence: https://github.com/trust-center, https://www.nist.gov/itl/ai-risk-management-framework, https://marketplace.fedramp.gov/products/FR2013522247
SOX — Assessment Required
GitHub, Inc. is a wholly-owned subsidiary of Microsoft Corporation (NASDAQ: MSFT), a publicly traded company subject to SOX. GitHub's financial controls and IT general controls (ITGCs) are incorporated into Microsoft's broader SOX compliance program. GitHub itself is not a separately publicly traded entity and does not file independent SEC reports. Risk is Low because SOX compliance is managed at the Microsoft parent level, and GitHub's internal controls are subject to Microsoft's annual SOX audit. The primary risk is ensuring GitHub's systems that support Microsoft's financial reporting maintain adequate ITGCs.
Evidence: https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=MSFT&type=10-K, https://github.com/trust-center, https://ghec.github.trust.page/
ISAE 3000 (source) — Assessment Required
ISAE 3000 is a framework for assurance engagements other than audits or reviews of historical financial information. It is commonly used for non-financial assurance reports, including sustainability/ESG reporting, privacy compliance attestations, and controls reporting. GitHub's SOC 2 reports (conducted under AT-C Section 205 in the US) are functionally equivalent to ISAE 3000-based assurance reports used in international contexts. Some of GitHub's enterprise customers in Europe may request ISAE 3000-compliant assurance reports rather than US AICPA-standard SOC 2 reports. Risk is Low because GitHub's existing SOC 2 Type II and ISO 27001 certifications provide substantial equivalent assurance, and ISAE 3000 is not a mandatory regulatory requirement for GitHub's operations.
Evidence: https://github.com/trust-center, https://ghec.github.trust.page/
Financials
Three-year financials
- 2024: revenue $2.0B
- 2023: revenue $2.0B
- 2022: revenue $1.0B
Financial Resilience Score: 9/10
GitHub's financial resilience is effectively equivalent to that of its parent company, Microsoft Corporation (AA+/Aaa credit rating), which acquired it in October 2018 for $7.5 billion in stock. As a wholly-owned subsidiary, GitHub has access to virtually unlimited capital, Microsoft's Azure cloud infrastructure, and its enterprise sales channels. This backing insulates GitHub from typical standalone SaaS liquidity or solvency risks. Operationally, GitHub holds a dominant market position as the de facto standard for source code hosting, with over 100 million developers on the platform and more than 90% of the Fortune 100 as customers. Its revenue has scaled from approximately $140M in 2016 to a $2B+ run rate in early 2024, representing an extraordinary ~40% CAGR. GitHub Copilot has emerged as one of the fastest-scaling SaaS products in history, driving over 40% of GitHub's revenue growth. However, standalone profitability is not disclosed and is widely believed to be under pressure due to high LLM inference costs. Competitive threats from Cursor, Anthropic Claude Code, Amazon Q Developer, and Google Gemini Code Assist are intensifying rapidly in the AI coding assistant space. Regulatory risks (Copilot copyright litigation, EU AI Act) and model supplier dependency (historically OpenAI) also warrant monitoring, though none threaten resilience given Microsoft's backing.
Key strengths: Wholly-owned subsidiary of Microsoft (AA+/Aaa credit), Dominant market position with 100M+ developers, 90%+ of Fortune 100 as customers, GitHub Copilot fastest-scaling SaaS product, $2B+ revenue run rate as of early 2024, ~40% revenue CAGR over 8 years, Diversified subscription revenue mix (Enterprise, Copilot, GHAS, Actions), Access to Azure infrastructure and Microsoft enterprise channels
Risk factors: Intensifying competition from Cursor, Claude Code, Amazon Q, Gemini Code Assist, High LLM inference costs pressuring Copilot margins, Historical dependency on OpenAI models (supplier/pricing risk), Ongoing Copilot copyright litigation (Doe v. GitHub), EU AI Act compliance and export control restrictions, Sensitivity to tech-sector hiring cycles, No disclosed standalone balance sheet, Standalone profitability believed to be under pressure
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.