Copilot Business or Enterprise: Data Retention and IP Questions
The difference between GitHub Copilot's Business and Enterprise plans on data retention and IP comes down to written terms, and terms change. Don't rely on a blog post, including this one, for the current retention period or indemnity wording. Use it to know which questions to ask and where to find the authoritative answers.
Here is a way to compare the two plans on the points a security reviewer or customer will care about, then document the answer so it survives the next plan change.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Which questions actually separate the two plans?
Whatever the vendor's marketing says, your comparison should come down to a short list. For each item, find the answer for the exact plan, in the current terms:
- Prompt and suggestion retention: are prompts, the code context sent with them and the returned suggestions stored, and for how long? Is that different for the chat feature versus inline completion?
- Training use: is your content used to train models, and is that off by default for the plan?
- IP protection: does the plan include an indemnity for generated output, and what conditions attach to it? Conditions often include enabling a filter for suggestions that match public code.
- Admin controls: can an administrator enforce settings across every seat, including blocking public-code matches and excluding files or repositories?
- Audit: is there an audit log of who used the tool and which settings changed?
- Processing location: where is data processed, and does that match your customer commitments?
Anything not written down in a current document is not an answer.
How do you get answers you can rely on?
Collect evidence in this order, and file it where your security team keeps vendor reviews:
- Read the current product terms and data protection addendum for the plan, and save a dated PDF.
- Read the vendor's trust center or security documentation for the retention and training statements.
- Ask the vendor in writing about anything ambiguous, such as chat versus completion retention, and keep the reply.
- Check the organization settings page after you enable a plan, because a setting that exists in documentation may still be off by default.
- Record the date. Re-check when you renew or when the vendor announces a plan change.
This file becomes the source when a customer's security questionnaire asks how you handle code sent to AI tools.
Which plan fits which situation?
Use your requirements to pick, not the plan names. A few scenarios:
Say you're a ten-person product team with no regulated customers. The business tier of an assistant with organization-managed seats and training off is often sufficient. The larger tier is worth a look only if you need a capability it adds, and you should name that capability before you pay for it.
Say you sell to banks or health systems whose contracts restrict where code and data flow. You need the retention and processing answers in writing, and probably an indemnity, before any developer touches a customer repository. That may point to the higher tier, or to no cloud assistant on certain repositories at all.
Say contractors work in your repos. Make sure they use seats under your organization, not personal accounts, because personal plans carry different terms and give you no controls.
What should you configure after you buy?
Buying the plan doesn't finish the job. Confirm and document these settings:
- Seats are assigned through your organization, with single sign-on if you use it.
- The public-code match filter is on, if your IP protection depends on it.
- Repositories or paths that hold secrets or restricted code are excluded from assistant context.
- Chat and inline completion policies are set deliberately rather than left at defaults.
- Someone owns the review of settings each quarter.
Then link these settings to your assistant usage policy and to how you check AI-generated code.
What should you tell customers who ask?
Answer with facts you can back up. State which tool and plan you use, that seats are managed through your organization, what data the terms say is retained and whether it's used for training, and which technical exclusions you've set. If you can't yet answer one point, say you're confirming it rather than guess. A precise, dated answer builds more trust than a confident summary that turns out to be out of date. Review it whenever the vendor changes terms, and compare with other options in the assistant comparison.
What Good Looks Like
You have a dated file of the vendor's current retention, training and IP terms for your plan, and your settings and customer answers match it.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
Does Copilot Business train on my code?
Check the current terms for your exact plan, because this is set by written policy that can change. Confirm the training statement and any admin setting in the vendor documentation and record the date you checked.
Does Copilot include IP indemnity?
Some plans include an indemnity for generated output, usually with conditions such as enabling a public-code match filter. Read the current terms for your plan and confirm the conditions with your attorney before relying on it.
How long does Copilot retain prompts?
That depends on the plan and on whether you use chat or inline completion, and it can change. Look up the current retention statement in the vendor's documentation, and get any unclear point confirmed in writing.
Should legal review the AI coding tool terms?
Yes, if you have customers with data or IP restrictions or need to rely on an indemnity. Legal should read the terms and the data protection addendum for the specific plan, not a summary.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
AI Coding Assistant Policy: What to Put in Yours
Write a short AI coding assistant policy: approved tools, data rules, review requirements, license and IP checks, and who enforces it.
Reviewing AI-Generated Code for Security: A Practical Checklist
Is AI-generated code secure? A review checklist covering hallucinated packages, missing authorization, unsafe input handling, secrets and scanning.
GitHub Copilot vs Cursor vs Codeium: AI Assistant Comparison
Compare GitHub Copilot, Cursor, and Codeium for engineering teams. Analyze code completions, multi-file edits, codebase indexing, and security.
Cursor vs GitHub Copilot for Data and Analytics Consultants
The unit of work for a data consultant is a query, a DAG node, or a notebook cell. How that changes the Cursor vs GitHub Copilot decision for client warehouses.
Cursor or GitHub Copilot: A Call for a SaaS Engineering Team
How a B2B SaaS engineering team should decide between Cursor and GitHub Copilot, from a real multi-file refactor to a two-pair pilot you can run in a week.
Is Your AI Coding Assistant Paying Off? How to Measure It
Measure whether AI coding assistants help: pick outcome metrics, run a fair comparison, avoid vanity numbers, and weigh seat cost against results.