GitLab's Customer Assurance Activities

Security documentation (such as SOC 2 Type 2, Pentest executive summary, etc.) available at Trust Center. (Click Get Access button at top right of page, enter company email address. This is the same process for customers and GitLab employees. More detailed instructions available below.)

Submit a Request

Customer Call Request Security Questionnaire Request Contract Review Request

The above are for GitLab Team Members only. Customers can upload questionnaires to GitLab’s Trust Center, or contact their GitLab Account Owner to initiate their requests. If a customer doesn’t know their Account Owner or does not yet have an assigned Account Owner, they can contact the sales team.

Customer Assurance Activity Requests Overview

GitLab Customers and Prospects conduct Security due diligence activities prior to contracting with GitLab. We recognize the importance of these reviews and have designed this procedure for GitLab Team Members to request Customer Assurance Activities.

GitLab Team Members

When submitting this request, ensure your customer is aware of GitLab’s Trust Center. The Trust Center will answer many of the customer’s questions and will enable us to provide the customer with a more efficient and comprehensive experience.

Please do not assign the issue. Field Security will assign the issue to the appropriate team member. Thank you!

Accessing the Trust Center

To access GitLab’s Trust Center:

  1. Navigate to trust.gitlab.com
  2. Click “Get Access” in the top right corner
  3. Enter your email address, and click “Continue”
  • Do not click “Log into GitLab’s workspace. That is for the admin portal.
  • Some documentation is public and does not require this process (ISO certificate (27001, 27017, 27018; 42001)).

The process is exactly the same for customers. If customers do not want to sign the click-wrap NDA, and they already have a fully-executed NDA in SFDC or an active GitLab subscription, we can bypass the click-wrap NDA on our end. Please note, this should be a last resort, as it will further delay access to the Trust Center. The fastest way to drive customers towards success is to encourage them to leverage the self-service nature of the Trust Center to its fullest extent. If you have any questions, please reach out #security_help Slack channel (tag @field-security).

For Questionnaires

The process will be handled in the Trust Center. Customers/prospects who have access to the Trust Center can directly upload questionnaires by clicking the Submit a Questionnaire link at the top of the Trust Center (they must have gone through the Get Access process described above in order to see the Submit a Questionnaire button).

As described above, Field Security has certain thresholds for completing customer questionnaires. See here in the Internal Handbook.

For Customer Calls

Please use the Customer Call Request or General Request buttons above and follow the instructions.

  • Be sure to include all requested information to expedite the process.
  • ARR or potential ARR is required
  • Customer calls require a preview of the topics the customer would like to cover to ensure we bring in any required subject matter experts for the call.
  • If you are unsure of which type it is, please include as much information as you can and our team will adjust as needed.

For Contract Reviews

Please use the Contract Review Box above and follow the instructions.

For RFP completion

Please follow the directions above for submission, and for more information about our RFP process please view our RFP page here.


Public Documentation

  • Search for general information about GitLab in our public Handbook, including policies and standards.
  • Review GitLab’s Product Documentation, including security settings to use.
  • Review GitLab’s Trust Center and download publicly available security assurance documents. To request our NDA Required documents, such as our SOC2 report, utilize the Get Access button in the Trust Center.

Self-Attestations

In the spirit of iteration, GitLab is continuously evolving our list of compliance self-attestations. Completed self-attestations are reviewed annually for continued applicability and can be found in our Trust Center.

Service Level Agreements

  • Security Questionnaires: 10 Business Day. SA or CSM will utlize the Knowledge Base and/or other self-service resources prior to requesting Field Security assistance. SA or CSM will ensure everyone on the Field Security team has access to any files or portals.
  • Contract Reviews: 5 Business Days. Field Security must be engaged in all relevant Contract Reviews.
  • Customer Calls: SA or CSM will provide context to the Customer or Prospects questions or concerns prior to the meeting. Field Security will provide a PowerPoint presentation with critical information about GitLab Security and specifics to the Customer or Prospect’s request. Field Security must be invited to all relevant Customer Meetings.
  • Security Documents: Managed through the Trust Center. Tag @field-security in #security_help on Slack with questions.

Exceptions

If the Account Owner or Customer Success point of contact feel they have sufficient knowledge and resources to complete a Customer Assessment, this procedure does not have to used. These exceptions will not be tracked.