HIPAA Compliance Checklist for 2025
TL;DR
- GitHub's published prices are Free at $0, Team at $4 per user per month and Enterprise from $21 per user per month, but GitHub's own pricing page footnotes both paid tiers as rates "for the first 12 months."
- Post-promotion Enterprise pricing is not published anywhere. You find out what year two costs when your rep tells you.
- The line items that actually grow are not the seats you bought. They are active committers on security add-ons, Copilot seats, and metered Actions, Codespaces and Packages usage.
- GitHub Advanced Security bills on unique committers who touched a private repo in the last 90 days, so your security bill moves with developer activity, not with headcount.
- CloudEagle.ai shows who actually uses GitHub and Copilot, reclaims the seats nobody touches, and puts real usage data in front of you before the intro year runs out.
Most GitHub pricing guides stop at the plan comparison. That is the easy part, and it is also the part that does not decide your bill.
The harder question is what happens in month thirteen. GitHub publishes $4 and $21 per user per month with an asterisk next to both, and behind that asterisk is a renewal conversation where the vendor knows your usage and you do not.
This guide covers the current GitHub pricing structure, the places the cost quietly compounds, and how to walk into that conversation with your own numbers.
Why GitHub Pricing Gets Harder To Control At Scale
GitHub looks like one of the simplest vendors in the stack. Three tiers, clean per-seat math, a public calculator. The complexity is not in the tiers. It is in everything billed next to them.

*GitHub lists both paid tiers as rates for the first 12 months. Source: GitHub pricing, verified July 2026. Re-confirm live figures before publishing.
Two things in that table drive more GitHub spend than the plan choice itself.
The first is the asterisk: Team and Enterprise are both published as first-year rates, and GitHub does not disclose what Enterprise costs after the promotional period.
The second is SAML SSO: It sits on Enterprise, which means the moment security requires single sign-on, your GitHub pricing moves from $4 to $21 per user. That is a five-fold jump triggered by a compliance requirement rather than a feature request, and it usually arrives with no warning to whoever owns the budget.
Where The Github Cost Actually Grows?
Seats are the predictable part. These are the lines that move on their own.
Security add-ons bill on active committers
- GitHub Advanced Security is no longer one SKU. It is now Secret Protection at $19 per committer per month and Code Security at $30 per committer per month.
- GitHub counts every committer who contributed to an enabled private repo in the last 90 days.
- Your security bill tracks developer activity, so a busy quarter costs more than a quiet one.
Copilot is a second per-seat product
- Copilot Business is $19 per user per month and Copilot Enterprise is $39, stacked on top of the GitHub seat.
- Premium requests beyond the plan allowance bill at $0.04 each, so heavy agent and chat usage pushes past the subscription without anyone approving it.
Metered services default toward spend
- Codespaces starts at $0.18 per hour of compute and $0.07 per GB of storage per month.
- Packages overage runs $0.25 per GB stored and $0.50 per GB of egress outside Actions workflows.
- Actions minutes bill per minute above the plan allowance at rates that vary by runner size and operating system.
Spend limits are a setting, not a default
- On Team and Enterprise, admins can raise the Codespaces and Actions spend ceiling.
- Anyone with admin rights can turn on a metered service, and that decision shows up on the invoice rather than in a purchase order.
Add those together and the shape of the problem is clear. GitHub bills you for who has a seat, who committed recently, and what ran. All three are questions about access and activity, and almost nobody has a current answer to any of them.
GitHub access tends to stay active long after projects or roles change. Read more →
How CloudEagle.ai Gets Github Spend Under Control
CloudEagle.ai works the problem in that order. It discovers every place GitHub and Copilot are being paid for, shows who actually uses them, then governs the access and gets the spend under control.
Each lever below stands on its own, and they compound when you run them together.

Right-size seats against real activity
Developer rosters move constantly. Contractors finish, teams reorganize, people move to a different repo set and stop touching the old one. The seat stays.

CloudEagle.ai reads usage across connected applications and flags accounts that have not logged in over a set window, so license management becomes a continuous process instead of a spreadsheet someone rebuilds each renewal.
On GitHub specifically, the important number is not how many seats you bought. It is how many of those seats belong to someone who committed in the last quarter, because that same population drives your Advanced Security bill.
Treat Copilot as its own line item
Copilot seats get handed out in an enthusiasm wave and reviewed almost never. At $19 or $39 per user per month, a batch of unused Copilot seats costs more than the underlying GitHub seats do.
CloudEagle.ai tracks AI tool adoption across the organization and monitors usage against budget thresholds, which is what turns Copilot from an invoice line into a managed one.
If you are evaluating that spend separately, the GitHub Copilot pricing guide breaks the tiers down in detail.
Match GitHub access to role
GitHub access tends to outlive the project that justified it. Outside collaborators keep repo access after an engagement closes.
Admin rights get granted for one migration and never revoked, and admin rights are exactly what lets someone raise a spend limit.
User access reviews put that population in front of the people who can make a call on it, on a schedule.

Automated onboarding and offboarding closes the other end, so a departure removes the seat instead of leaving it to be found at renewal. Enterprise gives you SCIM provisioning to enforce this, which is part of what you are paying the $21 for.
Walk into the renewal before the intro year ends
This is the lever that matters most for GitHub specifically, because of the twelve-month footnote. The renewal calendar puts the date in front of you with enough runway to act on it rather than react to it.

Price benchmarking and buying guides give you what comparable companies pay at your volume.
Together they change the shape of the conversation: instead of receiving a renewal quote and negotiating down from it, you open with your own utilization data and a benchmark range.
What Companies Actually Pay For GitHub
The three benchmark bands currently live on this post are unlabeled, so I have not carried them across rather than guess which SKU each one maps to. Pull the GitHub bands from the buyer's guide export, confirm the SKU label on each, and this section drops straight in.

CloudEagle.ai benchmark data, [2026]. Directional starting range for negotiation, not a quote.
Known GitHub-specific negotiation context to fold in here:
- Reps carry quarterly quotas rather than annual ones, so end of quarter carries more flexibility than end of year.
- Prepayment has moved pricing. Community reports put roughly 3% at a $25K commitment, closer to 5% at $70K and around 7% at $100K.
- Switching buyers have been offered free months to win the business.
- GitHub commits to 30 days notice before a price change.
- Organizations on Microsoft Unified Support have reported GitHub Premium Support included at no extra cost, which is worth checking before you buy it separately.
Best Practices for Controlling GitHub Costs
Run these before the renewal conversation, not during it.
- Pull the active committer count first. It sets your Advanced Security bill and it is usually smaller than your seat count.
- Audit Copilot seats separately from GitHub seats. They are different products with different adoption curves.
- Check every spend limit. Codespaces and Actions ceilings are admin-editable and default toward the permissive setting.
- Find every GitHub org on a corporate card. Consolidating scattered orgs into the enterprise agreement is usually the fastest single saving.
- Ask what year two costs, in writing, before you sign year one. The published rate expires and the replacement is not public.
- Time the ask to quarter end. Quarterly quotas mean the vendor's urgency and yours line up four times a year.
- Benchmark before you counter. A documented negotiation position beats a percentage you asked for because it sounded reasonable.
Which GitHub plan fits
- Free works for individual developers and small teams that can live inside 2,000 Actions minutes a month and do not need private-repo collaboration controls.
- Team suits growing engineering orgs that need code owners, required reviewers and repository rules, and are not yet under an SSO mandate.
- Enterprise is the answer when you need SAML SSO, SCIM, audit log access, Enterprise Managed Users or data residency. Most organizations land here because of a compliance requirement rather than a feature one.
Github Alternatives Worth Benchmarking Against
Having a credible alternative is leverage even when you have no intention of moving.
- GitLab bundles CI/CD, security scanning and project management into one platform and offers self-managed deployment.
- Bitbucket fits teams already standardized on Atlassian, with native Jira integration.
- Azure DevOps is the other Microsoft option and sometimes prices differently inside an existing Microsoft agreement.
- Gitea is a lightweight open-source, self-hosted option for teams that want to own the infrastructure.
Want to understand GitHub Copilot pricing and AI coding costs too? Read more →
Get Your GitHub Pricing Under Control Before The Renewal
GitHub's list price is honest about what it is. It is a first-year rate on a platform where the bill grows through committers, Copilot seats and metered usage that nobody signed off on individually.
CloudEagle.ai gives you the one thing the pricing page cannot: what your organization actually uses.
Seats against activity, Copilot against adoption, every GitHub org across every payment method, and a benchmark range to open the renewal with.
Book a demo and see your GitHub spend in one view before the intro year ends.
Frequently Asked Questions
1. Is GitHub pricing per user or per repository?
Per user. Team and Enterprise both bill per seat for private repository collaborators. Advanced Security is the exception and bills per unique committer active in the last 90 days.
2. Does GitHub Enterprise pricing stay at $21 per user?
GitHub publishes $21 per user per month as a first-year rate. Post-promotional Enterprise pricing is not disclosed publicly and comes through sales, so confirm year two terms before signing year one.
3. Why did our GitHub bill go up without adding users?
Usually metered services or committer counts. Actions minutes, Codespaces compute, Packages egress and Copilot premium requests all bill on consumption, and Advanced Security recalculates as committer activity changes.
4. Do we need Enterprise just for SSO?
Yes for SAML single sign-on on GitHub Enterprise Cloud. It is the most common reason teams move from $4 to $21 per user, which makes it worth modelling the full cost before the security deadline forces the decision.
5. How do we know if we are overpaying for GitHub?
Compare seats purchased against seats used in the last 30 days, check Copilot adoption separately, and benchmark your per-user rate against what companies at your license volume pay. Any gap is negotiating room.






.avif)




.avif)
.avif)




.png)


