{
  "slug": "gitlab",
  "category": "code-hosting",
  "name": "GitLab",
  "description": "Git hosting with CI/CD, issue tracking and project management, offered as the hosted GitLab.com service or as software to self-host.",
  "website": "https://gitlab.com",
  "source": "https://gitlab.com/gitlab-org/gitlab",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 63,
  "coverage": 100,
  "summary": "GitLab scores 63 out of 100 (grade C) on the code hosting criteria. It meets 4 of 8 criteria: open source, transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
  "url": "https://privacyratings.com/code-hosting/gitlab/",
  "markdown": "https://privacyratings.com/code-hosting/gitlab/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://gitlab.com/gitlab-org/gitlab/-/blob/master/LICENSE",
      "note": "All code is public, including the ee directory used by GitLab.com. The Community Edition is MIT and the Enterprise Edition code uses the source-available GitLab Enterprise Edition license."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The home page loads Optimizely (automated test)."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://about.gitlab.com/privacy/",
      "note": "Funded by subscriptions, but the privacy statement says cookies are used for interest-based advertising based on online activity."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://trust.gitlab.com/",
      "note": "SOC 2 reports and penetration test summaries from independent auditors are only available on request through the Trust Center."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://handbook.gitlab.com/handbook/legal/privacy/transparency-reports/",
      "note": "Publishes yearly law enforcement reports with request counts by type."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://handbook.gitlab.com/handbook/legal/privacy/transparency-reports/",
      "note": "Policy is to notify users of requests for their data unless prohibited by law or a court order."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=gitlab.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=gitlab.com",
      "note": "Grade C (50/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "C",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "OneTrust",
        "host": "cdn.cookielaw.org",
        "effect": "none"
      },
      {
        "name": "Optimizely",
        "host": "cdn.optimizely.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T07:19:54.497Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}