Security Policies Github Sirt Description Rfc 2350 (GitHub)

Updated 17 October 2025

This document describes the GitHub Security Incident Response Team (SIRT), outlining its mission to protect GitHub's platform and user data by maintaining confidentiality, integrity, and availability. It provides essential contact information, details the team's operational policies, and explains the scope of its incident response and proactive security activities. The document also guides users and customers on how to report vulnerabilities and access support.

GitHub SIRT description RFC 2350

Document Information

TLP: CLEAR

Date of Last Update

Version 1.01, updated 2025-01-30.

Distribution List for Notifications

There is no distribution list for changes to this document.

Locations where this Document May Be Found

The current version of this document may be found at:

https://docs.github.com/site-policy/security-policies/github-sirt-description-rfc-2350

Contact Information

Name of the Team

GitHub Security Incident Response Team (SIRT)

Subteams:

Corporate Security Incident Response Team (CSIRT)

Product Security Incident Response Team (PSIRT)

Bug Bounty

Address

GitHub SIRT 88 Colin P. Kelly Jr. St. San Francisco, CA 94107 United States

Time Zone

Our team mainly works in the contiguous United States and keeps to these hours:

EST/EDT

CST/CDT

MST/MDT

PST/PDT

Telephone Number

None available.

Facsimile Number

None available.

Other Telecommunication

None available.

Electronic Mail Address

security(at)github(dot)com

This relays email to the human(s) on duty for GitHub SIRT.

Public Keys and Encryption Information

GitHub SIRT has a PGP public key:

Key ID: 78DCCCE9923E5CFB3CAA5D5AB79DBDA3BE944D9E

Key expiry: 2025-09-12

-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEZQHKOxYJKwYBBAHaRw8BAQdAzvtu6OfJTspbWTVVU2uDeljmfEr1qYkvD25w NKB2twq0JUdpdEh1YiBTZWN1cml0eSA8c2VjdXJpdHlAZ2l0aHViLmNvbT6ImQQT FgoAQRYhBHjczOmSPlz7PKpdWredvaO+lE2eBQJlAco7AhsDBQkDwmcABQsJCAcC AiICBhUKCQgLAgQWAgMBAh4HAheAAAoJELedvaO+lE2e1voA/31lJyof7nWI1Mxs x3MHhwp5sFh2P/pFucuNKb7ciwMMAQCCAk39cSFs2WWw8aZC7lqXNJcFiMn0r+wm i6I3pWjiA7g4BGUByjsSCisGAQQBl1UBBQEBB0C0jKXWh6G8atXCJi2xsy71+NzX 0Y2WN8yj3f59MGHYfAMBCAeIfgQYFgoAJhYhBHjczOmSPlz7PKpdWredvaO+lE2e BQJlAco7AhsMBQkDwmcAAAoJELedvaO+lE2eozABAIbzLwvaACiKFzXYjp9Zpenv GEHeqggLGzHpEheyoBMkAP96NI0kzYvj+zhJZ/4Y3TIDZaOD8OXezwia9E2Bxf5O Aw== =4+TC
-----END PGP PUBLIC KEY BLOCK-----

Team Members

The list of team members is not publicly available.

Other Information

None available.

Points of Customer Contact

Vulnerabilities should be reported to our bug bounty program:
https://bounty.github.com

GitHub customers should contact their account manager or GitHub Support for first level support and escalations:
https://support.github.com

Other security related communications can be directed to our email address detailed in Section 2.7.

Charter

Mission Statement

GitHub is committed to maintaining the confidentiality, integrity, and availability of both its platform and the intellectual property and personal information of its users, customers, and employees. In order to ensure these principles are upheld, GitHub maintains robust vulnerability management, incident response, and threat hunting capabilities.

Constituency

Our constituency is any individual or organization that uses a GitHub product or service, as well as GitHub employees, contractors, and GitHub Inc.

Some examples of GitHub products and services are:

GitHub.com

GitHub Enterprise Server

GitHub Actions

GitHub Desktop

GitHub CLI

GitHub API

npm

Sponsorship and/or Affiliation

GitHub SIRT is a team within GitHub. Funding is provided by GitHub.

Authority

GitHub SIRT operates under the authority of the Chief Information Security Officer of GitHub.

Policies

Types of Incidents and Level of Support

GitHub SIRT is authorized to address all types of computer security incidents which occur, or threaten to occur, within its constituency.

The level of support depends on the type and severity of the given security incident, the number of affected entities within our constituency, and our resources at the time.

Co-operation, Interaction and Disclosure of Information

GitHub SIRT takes every effort to safely and securely share information with affected parties during incident response situations while respecting the privacy and trust of our constituents.

Communication and Authentication

GitHub SIRT makes use of the Traffic Light Protocol (TLP) for information sharing.

Email is the preferred method of communication. All sensitive information should be encrypted using the GitHub SIRT PGP key (as detailed in Section 2.8) prior to sending.

Services

Incident Response

GitHub SIRT is responsible for incident response internally at GitHub where at least one member of the constituency is affected.

GitHub SIRT does not provide incident response services for customers. Every effort is made to provide timely and accurate information during security incidents to affected customers so they can conduct their own investigations and respond appropriately. See section 2.11 for customer points of contact.

Incident Triage

GitHub SIRT carries out the following activities for incident triage:

Security signals are collected and interpreted to determine risk, severity, and priority.

Investigation as to whether an incident occurred and what its effect and impact was.

This list is not exhaustive.

Incident Coordination

GitHub SIRT carries out the following activities for incident coordination:

Situational awareness and analysis for stakeholders such as engineering, legal, and support teams.

Command role with authority to direct resources as required.

External coordination with affected or involved third-parties.

This list is not exhaustive.

Incident Resolution

GitHub SIRT carries out the following activities for incident resolution:

Engages relevant internal teams to eradicate, restore, and secure.

Collection and storage of evidence for internal use as well as potential law enforcement involvement.

Notification to affected constituents.

Postmortem authoring with lessons learned and post-incident repair items.

This list is not exhaustive.

Proactive Activities

GitHub SIRT develops, maintains, and operates threat hunting and detection tools and techniques to proactively identify risks and threats.

Work is also done on education, preparation, workflow development, and community outreach.

Incident Reporting Forms

None available. Please review Section 2.11 for reporting guidance.

Disclaimers

While every precaution will be taken in the preparation of information, notifications and alerts, GitHub SIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained within.

About this template

What is this template?

Security Policies Github Sirt Description Rfc 2350 (GitHub) is a free, ready-to-use Cybersecurity template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.

When should you use it?

Reach for this Cybersecurity template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with United States of America and California (US) in mind, though you should always review the final wording against the laws that apply to you.

What's typically included?

A well-drafted Cybersecurity usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.

Jurisdiction
United States of America
California (US)
Document info
HTML document. Document created on Fri Sep 12th, 2025. Last updated on Fri Oct 17th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
OLOpen Legal Library
Amending Share Capital (Shareholder Resolution)
OLOpen Legal Library
Pocket Privacy Policy by Mozilla
OLOpen Legal Library
Cell Phone Policy by EasyLegalDocs
OLOpen Legal Library
Sample Code of Conduct Policy (NVCA)
OLOpen Legal Library
Anti-Bribery and Corruption Policy by EasyLegalDocs
OLOpen Legal Library
Approving Director Remuneration (Shareholder Resolution)