At GitLab, we're committed to Information Security. It is GitLab’s mission to make it so that everyone can contribute, and it's our Security Division's mission to enable everyone to innovate and succeed on a safe, secure, and trusted DevSecOps platform. To learn more, visit the security section of our handbook.
GitLab's AI Transparency Center can be found here.
- Are cryptographically secure and standardized network protocols implemented for the management, import, and export of data?
- Is the disaster response plan updated at least annually, and when significant changes occur?
- Are risk factors associated with all organizations within the supply chain periodically reviewed by CSPs?
- Is a process to conduct periodic security assessments for all supply chain organizations defined and implemented?
- Are policies and procedures for security incident management, e-discovery, and cloud forensics established, documented, approved, communicated, applied, evaluated, and maintained?
Trust Center Updates
The 2025 GitLab.com and GitLab Dedicated SOC 2 reports are now available on the Trust Center. GitLab's ISO certificate, which covers ISO 27001, 27017, and 27018, is also available on the Trust Center in English, French, German, and Japanese.
The 2024 GitLab.com and GitLab Dedicated SOC2 reports are now available on the trust center. GitLab's ISO certificate, which covers ISO 27001, 27017, and 27018 is also available on the trust center in English, French, German, and Japanese.
GitLab's PCI DSS AoC - SAQ D for Service Providers is now available for GitLab.com. Please visit the Trust Center to download the Attestation of Compliance (AoC), Responsibility Matrix, and Pentest Letter of Attestation.
GitLab's PCI DSS AoC - SAQ D for Service Providers is now available for GitLab.com. Please visit the Trust Center to download the AoC and the Responsibility Matrix.
GitLab has published its FY26 Penetration Test Executive Summary reports. The reports cover both GitLab.com and GitLab Dedicated. Please download the reports from the trust center at your convenience.
GitLab has published its FY25 Penetration Test Executive Summary report. The report covers both GitLab.com and GitLab Dedicated. Please download the report from the trust center at your convenience.











