The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
CCPA
Publicly advertised on the organization’s trust center.
-
CSA STAR
Publicly advertised on the organization’s trust center.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
ISO 27017
Publicly advertised on the organization’s trust center.
-
ISO 27018
Publicly advertised on the organization’s trust center.
-
ISO 42001
International standard for AI management systems. Adoption is early; advertising it is a notable signal.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
TISAX
Publicly advertised on the organization’s trust center.
-
Cyber Essentials
Publicly advertised on the organization’s trust center.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Security & compliance hiring
Open roles on the organization’s public job board, a signal of active investment in security and compliance.
- Director of Engineering, Security Factory
- Intermediate Software Engineer, Security Factory: Vulnerability Management
- Principal Security Awareness & Human Risk Engineer
- Principal Security Researcher
- Senior Director, Internal Audit
- Senior Manager, Internal Audit - Audit Automation & Technology Risk
- Senior Manager, Product Security Engineering (Security Posture & Supply Chain)
- Senior Security Assurance Engineer
- Senior Security Compliance Engineer, Public Sector
- Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA
- Senior Software Engineer (Ruby), Security Platform: Authorization
- Senior Software Security Engineer
- Staff Backend Engineer, Software Supply Chain Security
- Staff Corporate Security Engineer
- Staff Infrastructure Security Engineer (EMEA/APJ)
- Staff Infrastructure Security Engineer (USA)
- Staff Security Engineer, IAM
- Staff Security Researcher
Named as a subprocessor by
Organizations in the Trust Index that disclose Gitlab as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.