Assuming your confidential code is in private repos, you're fine. From their FAQ:
> [GitHub Copilot] has been trained on natural language text and source code from publicly available sources, including code in public repositories on GitHub.
You can't know (although they claim it was trained only on public code, presumably including proprietary public or leaked code). GPL folks are wondering if it is possible to convert proprietary code to GPL through CoPilot.
I think you can pretty safely know. People store sensitive information, passwords, keys, etc in private repos aaaall the time. It would be an entirely unnecessary complexity for copilot to try to filter out that sensitive information. It's not like there's a deficiency of public code on GitHub. It wouldn't make any sense to train on private repos.
All that stuff is in public repos too, so really they should filter out those things from public repos too. The only difference I can see is that private repos are usually proprietary and GitHub didn't want to anger their paying customers, who usually have proprietary code on GitHub.