Skip to main content
GitLab logo

GitLab

Security and trust center evidence

A complete DevOps platform delivered as a single application.

gitlab.comDevOps and observabilityLast verified 17 Sep 2026

Summary

GitLab has 3 registry-verified rows and 9 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 2026-09-17, GitLab states on its trust centre that it holds SOC 2, and no auditor or period end is provided. As of 2026-09-17, GitLab is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 2025-05-15 by auditor Fortreum, LLC. As of 2026-09-17, GitLab is listed in the CSA STAR registry at STAR Level 1 self-assessment (CAIQ), Trusted Cloud Provider, issued 2020-04-13. As of 2026-09-17, GitLab is listed in the EU-US Data Privacy Framework registry as active, with certification issued 2026-04-29 and expiring 2027-04-29. As of 2026-09-17, GitLab states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001, GDPR, PCI DSS, CCPA/CPRA, and TISAX, and no HIPAA BAA evidence or subprocessor list evidence was found.

  • FedRAMP: listed in FedRAMP registry as FedRAMP Authorized, issued 2025-05-15, auditor Fortreum, LLC (as of 2026-09-17).
  • EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, SW-US, UK Extension), issued 2026-04-29, expires 2027-04-29 (as of 2026-09-17).
  • SOC 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001, GDPR, PCI DSS, CCPA/CPRA, TISAX: vendor states on its trust centre it holds these frameworks (as of 2026-09-17); no HIPAA BAA evidence found.

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among devops and observability vendors

3verified rows

Category median 1, across 90 indexed devops and observability vendors. GitLab has more verified rows than 100 percent of them.

ci/cddevops platformgit repositoryversion control

Compliance grid

Subprocessors

No subprocessor list captured yet.

Change history

  1. 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
  2. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  3. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  4. 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
  5. 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
  6. 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
  7. 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
  8. 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
  9. 17 Sep 2026TISAX evidence addedA TISAX row entered the index with state Vendor-stated.

Similar vendors with evidence

Related by product tags and the DevOps and observability category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.