If I was managing the IT dept for a government security contractor I wouldn't be using cloud email.
If I'm knocking up the next cloud service mashup, I'm fairly sure I'd be storing the code in a private github repo until there was a need or decision to change.
So yes, sensitive code is stored in public cloud sites. Sensitive emails are too.
https://help.github.com/enterprise/11.10.340/admin/articles/...
That said, my understanding is that authentication even for Github Enterprise is done through Github itself. (Someone please correct me if I'm wrong)
The enterprise product is stand-alone, it doesn't talk to the cloud version.
Once might have the same reservations about something like Heroku - or really any cloud provider - given that at some point, you are pushing code to a server that is owned by another company whose security you cannot audit.
(From my prior experience working for a publicly traded US company)