
GitLab
Security and trust center evidence
A complete DevOps platform delivered as a single application.
Summary
GitLab has 3 registry-verified rows and 9 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 2026-09-17, GitLab states on its trust centre that it holds SOC 2, and no auditor or period end is provided. As of 2026-09-17, GitLab is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 2025-05-15 by auditor Fortreum, LLC. As of 2026-09-17, GitLab is listed in the CSA STAR registry at STAR Level 1 self-assessment (CAIQ), Trusted Cloud Provider, issued 2020-04-13. As of 2026-09-17, GitLab is listed in the EU-US Data Privacy Framework registry as active, with certification issued 2026-04-29 and expiring 2027-04-29. As of 2026-09-17, GitLab states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001, GDPR, PCI DSS, CCPA/CPRA, and TISAX, and no HIPAA BAA evidence or subprocessor list evidence was found.
- FedRAMP: listed in FedRAMP registry as FedRAMP Authorized, issued 2025-05-15, auditor Fortreum, LLC (as of 2026-09-17).
- EU-US Data Privacy Framework: listed in DPF registry as active (EU-US, SW-US, UK Extension), issued 2026-04-29, expires 2027-04-29 (as of 2026-09-17).
- SOC 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001, GDPR, PCI DSS, CCPA/CPRA, TISAX: vendor states on its trust centre it holds these frameworks (as of 2026-09-17); no HIPAA BAA evidence found.
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among devops and observability vendors
3verified rows
Category median 1, across 90 indexed devops and observability vendors. GitLab has more verified rows than 100 percent of them.
ci/cddevops platformgit repositoryversion control
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Fortreum, LLC
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO/IEC 27001 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ), Trusted Cloud Provider
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
TISAXVendor-statedVendor states TISAX on its trust centre
as of 17 Sep 20261 source
No public evidence yet for HIPAA, Cyber Essentials, ISO 27701. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
No DPA, BAA or subprocessor list has been captured from a public page yet. Registry rows above do not depend on this. Check the vendor trust centre.
Subprocessors
No subprocessor list captured yet.
Change history
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
- 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026TISAX evidence addedA TISAX row entered the index with state Vendor-stated.
Similar vendors with evidence
Related by product tags and the DevOps and observability category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.