GitHub Copilot history: answering an audit or security questionnaire
A customer asks how AI-generated code is reviewed and retained. What do we show them?
Why this is hard
The question has stopped being hypothetical: customer security questionnaires now ask about prompt logging and retention directly. The answer has to be a system rather than a description of good intentions, and it has to cover a period that already happened.
What GitHub Copilot specifically does to you here
Sessions are on disk with no expiry, which is the good part. The problem for an audit is identification: directories are named after a hash of the workspace path, so proving which project a given set of sessions belongs to means reading each workspace.json by hand.
cat "$HOME/Library/Application Support/Code/User/workspaceStorage/"*/workspace.json | head -3
Where GitHub Copilot keeps this in the first place: ~/Library/Application Support/Code/User/workspaceStorage/<hash>/chatSessions/. History is keyed to the workspace path. Rename or move the project and the chat panel comes up empty.
What a working answer looks like
A working answer means a retained, timestamped record you can point at — with a retention policy you chose rather than inherited from a tool's default.
Start by measuring what you have. npx promptwake doctor reports what every AI tool on the machine is holding and how much of it sits inside a deletion window — no account, writes nothing, sends nothing anywhere. If the conclusion is that the record should not depend on one laptop, that is what PromptWake captures: prompt, response and the resulting diff, local by default and synced into a shared timeline on the paid tiers.
