
GitLab
Compliance evidence
A complete DevOps platform delivered as a single application.
Compliance grid
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Fortreum, LLC
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ), Trusted Cloud Provider
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
TISAXVendor-statedVendor states TISAX on its trust centre
as of 17 Sep 20261 source
No public evidence yet for HIPAA, Cyber Essentials, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Official framework marks identify the scheme each row is about; the CertReports state chip beside each mark is our assessment of the public evidence. How states are decided.