Trust Center

Start your security review
View & download sensitive information
Ask for information
Search items
ControlK

At GitLab, we're committed to Information Security. It is GitLab’s mission to make it so that everyone can contribute, and it's our Security Division's mission to enable everyone to innovate and succeed on a safe, secure, and trusted DevSecOps platform. To learn more, visit the security section of our handbook.

GitLab's AI Transparency Center can be found here.

Documents

Featured Documents

REPORTSPenetration Test Executive Summary (Pentest)
Acceptable Use Policy
Access Management Policy
Audit Logging Policy
View more
Knowledge Base (FAQ)
    Are change management baselines established for all relevant authorized changes on organizational assets?
    Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?
    Are baseline requirements to secure different applications established, documented, and maintained?
    Are background verification policies and procedures of all new employees (including but not limited to remote employees, contractors, and third parties) established, documented, approved, communicated, applied, evaluated, and maintained?
    Are audit records generated, and do they contain relevant security information?
View more
Trust Center Updates

PCI DSS AoC is Now Available

Copy link
Compliance

GitLab's PCI DSS AoC - SAQ D for Service Providers is now available for GitLab.com. Please visit the Trust Center to download the AoC and the Responsibility Matrix.

2024/2025 Bridge Letter is Now Available

Compliance

GitLab's 2024/2025 SOC2 Bridge Letter is now available for both GitLab.com and GitLab Dedicated.

Updated SOC Reports and ISO Certificate!

Compliance

The 2024 GitLab.com and GitLab Dedicated SOC2 reports are now available on the trust center. GitLab's ISO certificate, which covers ISO 27001, 27017, and 27018 is also available on the trust center in English, French, German, and Japanese.

Updated Penetration Test Executive Summary

General

GitLab has published its FY25 Penetration Test Executive Summary report. The report covers both GitLab.com and GitLab Dedicated. Please download the report from the trust center at your convenience.

Documents Updated with Japanese, German, and French Translations

General

GitLab has updated the following documents for both GitLab.com and GitLab Dedicated with Japanese, German, and French translations:

  • Securing Customer Data Report
  • GitLab Technical Paper - Securing GitLab's Supply Chain
  • CAIQ
  • ISO Certificate
  • ISO 27001 Summary Letter
If you think you may have discovered a vulnerability, please send us a note.
Report issue
Built onSafeBase by Drata Logo