Security Policies Github Sirt Description Rfc 2350 (GitHub)

GitHubUpdated 17 Oct 2025

This document describes the GitHub Security Incident Response Team (SIRT), outlining its mission to protect GitHub's platform and user data by maintaining confidentiality, integrity, and availability. It provides essential contact information, details the team's operational policies, and explains the scope of its incident response and proactive security activities. The document also guides users and customers on how to report vulnerabilities and access support.

GitHub SIRT description RFC 2350

Document Information

TLP: CLEAR

Date of Last Update

Version 1.01, updated 2025-01-30.

Distribution List for Notifications

There is no distribution list for changes to this document.

Locations where this Document May Be Found

The current version of this document may be found at:

https://docs.github.com/site-policy/security-policies/github-sirt-description-rfc-2350

Contact Information

Name of the Team

GitHub Security Incident Response Team (SIRT)

Subteams:

Corporate Security Incident Response Team (CSIRT)

Product Security Incident Response Team (PSIRT)

Bug Bounty

Address

GitHub SIRT 88 Colin P. Kelly Jr. St. San Francisco, CA 94107 United States

Time Zone

Our team mainly works in the contiguous United States and keeps to these hours:

EST/EDT

CST/CDT

MST/MDT

PST/PDT

Telephone Number

None available.

Facsimile Number

None available.

Other Telecommunication

None available.

Electronic Mail Address

security(at)github(dot)com

This relays email to the human(s) on duty for GitHub SIRT.

Public Keys and Encryption Information

GitHub SIRT has a PGP public key:

Key ID: 78DCCCE9923E5CFB3CAA5D5AB79DBDA3BE944D9E

Key expiry: 2025-09-12

-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEZQHKOxYJKwYBBAHaRw8BAQdAzvtu6OfJTspbWTVVU2uDeljmfEr1qYkvD25w NKB2twq0JUdpdEh1YiBTZWN1cml0eSA8c2VjdXJpdHlAZ2l0aHViLmNvbT6ImQQT FgoAQRYhBHjczOmSPlz7PKpdWredvaO+lE2eBQJlAco7AhsDBQkDwmcABQsJCAcC AiICBhUKCQgLAgQWAgMBAh4HAheAAAoJELedvaO+lE2e1voA/31lJyof7nWI1Mxs x3MHhwp5sFh2P/pFucuNKb7ciwMMAQCCAk39cSFs2WWw8aZC7lqXNJcFiMn0r+wm i6I3pWjiA7g4BGUByjsSCisGAQQBl1UBBQEBB0C0jKXWh6G8atXCJi2xsy71+NzX 0Y2WN8yj3f59MGHYfAMBCAeIfgQYFgoAJhYhBHjczOmSPlz7PKpdWredvaO+lE2e BQJlAco7AhsMBQkDwmcAAAoJELedvaO+lE2eozABAIbzLwvaACiKFzXYjp9Zpenv GEHeqggLGzHpEheyoBMkAP96NI0kzYvj+zhJZ/4Y3TIDZaOD8OXezwia9E2Bxf5O Aw== =4+TC
-----END PGP PUBLIC KEY BLOCK-----

Team Members

The list of team members is not publicly available.

Other Information

None available.

Points of Customer Contact

Vulnerabilities should be reported to our bug bounty program:
https://bounty.github.com

GitHub customers should contact their account manager or GitHub Support for first level support and escalations:
https://support.github.com

Other security related communications can be directed to our email address detailed in Section 2.7.

Charter

Mission Statement

GitHub is committed to maintaining the confidentiality, integrity, and availability of both its platform and the intellectual property and personal information of its users, customers, and employees. In order to ensure these principles are upheld, GitHub maintains robust vulnerability management, incident response, and threat hunting capabilities.

Constituency

Our constituency is any individual or organization that uses a GitHub product or service, as well as GitHub employees, contractors, and GitHub Inc.

Some examples of GitHub products and services are:

GitHub.com

GitHub Enterprise Server

GitHub Actions

GitHub Desktop

GitHub CLI

GitHub API

npm

Sponsorship and/or Affiliation

GitHub SIRT is a team within GitHub. Funding is provided by GitHub.

Authority

GitHub SIRT operates under the authority of the Chief Information Security Officer of GitHub.

Policies

Types of Incidents and Level of Support

GitHub SIRT is authorized to address all types of computer security incidents which occur, or threaten to occur, within its constituency.

The level of support depends on the type and severity of the given security incident, the number of affected entities within our constituency, and our resources at the time.

Co-operation, Interaction and Disclosure of Information

GitHub SIRT takes every effort to safely and securely share information with affected parties during incident response situations while respecting the privacy and trust of our constituents.

Communication and Authentication

GitHub SIRT makes use of the Traffic Light Protocol (TLP) for information sharing.

Email is the preferred method of communication. All sensitive information should be encrypted using the GitHub SIRT PGP key (as detailed in Section 2.8) prior to sending.

Services

Incident Response

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

United States note

This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.

Jurisdiction
United States of America
California (US)
Document info
HTML document. Document created on Fri Sep 12th, 2025. Last updated on Fri Oct 17th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
US
Security Policies Github Sirt Description Rfc 2350 (GitHub)
This document provides a standardized description of a Computer Security Incident Response Team (CSIRT) following the RFC 2350 protocol. It details contact methods, the team's mission and authority, and specific procedures for handling security incidents.
Updated 13 Aug 2026
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026
US
Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub)
This policy establishes a framework for security researchers to find and report vulnerabilities in a company's software. It introduces a bug bounty program that offers financial rewards for coordinated disclosure and provides links to specific legal safe harbor terms.
Updated 13 Aug 2026
US
Firefox Relay Privacy Notice by Mozilla
This privacy notice outlines how an email alias service handles user data, including the processing of email messages and account information. It details data collection for Firefox Accounts, interaction logs, and technical device data while clarifying that email content is not read or stored.
Updated 13 Aug 2026
US
Acceptable Use Policies Github Active Malware Or Exploits (GitHub)
This policy prohibits the use of a platform for unlawful technical attacks, including the delivery of malicious executables and the management of command-and-control servers. It establishes a framework for hosting dual-use security research content while outlining conditions under which access to specific content may be restricted to disrupt ongoing malware campaigns.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.