Privacy Ratings

Code hosting

GitLab privacy rating

Git hosting with CI/CD, issue tracking and project management, offered as the hosted GitLab.com service or as software to self-host.

Summary

GitLab scores 63 out of 100 (grade C) on the code hosting criteria. It meets 4 of 8 criteria: open source, transparency report, tells users about requests and TLS configuration. It partly meets no ads or data sales and independent audit. It does not meet no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.

Score 63 out of 100. How scoring works

Criteria

  • Yes

    Open source Weight 3 of 3 Source-available

    Is all the source code needed to run the product public?

    All code is public, including the ee directory used by GitLab.com. The Community Edition is MIT and the Enterprise Edition code uses the source-available GitLab Enterprise Edition license.

    gitlab.com

  • No

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    The home page loads Optimizely (automated test).

  • Partial

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Funded by subscriptions, but the privacy statement says cookies are used for interest-based advertising based on online activity.

    about.gitlab.com

  • Partial

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    SOC 2 reports and penetration test summaries from independent auditors are only available on request through the Trust Center.

    trust.gitlab.com

  • Yes

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    Publishes yearly law enforcement reports with request counts by type.

    handbook.gitlab.com

  • Yes

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    Policy is to notify users of requests for their data unless prohibited by law or a court order.

    handbook.gitlab.com

Automated tests

  • Yes

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A+

    ssllabs.com

  • No

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade C (50/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

Other code hosting

All 9 code hosting