Atlassian HipChat was breached. Time to reset your password.
blog.hipchat.com
blog.hipchat.com
(From my prior experience working for a publicly traded US company)
Once might have the same reservations about something like Heroku - or really any cloud provider - given that at some point, you are pushing code to a server that is owned by another company whose security you cannot audit.
That said, my understanding is that authentication even for Github Enterprise is done through Github itself. (Someone please correct me if I'm wrong)
The enterprise product is stand-alone, it doesn't talk to the cloud version.
If I was managing the IT dept for a government security contractor I wouldn't be using cloud email.
If I'm knocking up the next cloud service mashup, I'm fairly sure I'd be storing the code in a private github repo until there was a need or decision to change.
So yes, sensitive code is stored in public cloud sites. Sensitive emails are too.
https://help.github.com/enterprise/11.10.340/admin/articles/...