GitLab can help you with your SOX compliance

Building SOX Compliant Applications with GitLab


In 2002 the United States Congress passed the Sarbanes-Oxley Act, also known as SOX to help protect the public from fraudulent practices by corporations. For publicly traded companies, SOX compliance is critical. The software development process of these organizations must be designed, developed, tested, and deployed in ways that adhere to SOX compliance.

GitLab can help you meet SOX IT General Controls (ITGC) compliance requirements by providing you a powerful set of features that support best practice in software development from a single platform.

New features are added to GitLab on the 22nd of every month.

Access controls

GitLab provides an access control system that allows you to easily maintain the principle of least privilege, ensuring that your users only have access to what they need to do their job.

SolutionTierDedicated, SaaS / Self-Managed
LDAP synchronizationPremiumSelf-Managed
SAML group syncPremiumDedicated, SaaS & Self-Managed
SCIM for Self-Managed InstancesPremiumSelf-Managed
Users with Minimal accessPremiumDedicated, SaaS & Self-Managed
User permissions exportPremiumSelf-Managed
Account deletionPremiumDedicated, SaaS & Self-Managed
Group access and permissionsPremiumDedicated, SaaS & Self-Managed
Restrict project and group access by using impersonationPremiumDedicated, SaaS & Self-Managed
Confidential issuesPremiumDedicated, SaaS & Self-Managed
Protected branchesPremiumDedicated, SaaS & Self-Managed
Auditor usersPremiumSelf-Managed

IT security

GitLab provides many built in capabilities such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Container Scanning, Dependency Scanning, and Vulnerability Reporting.

SolutionTierDedicated / SaaS / Self-Managed
Disable signupsPremiumSelf-Managed
Installation securityPremiumDedicated, SaaS & Self-Managed
Two-factor authPremiumSaaS & Self-Managed
Verified authors with signed commitsPremiumDedicated, SaaS & Self-Managed
Ensure removed users cannot invite themselves backPremiumDedicated, SaaS & Self-Managed
Secret detectionPremiumDedicated, SaaS & Self-Managed
Group and project access reportPremiumSaaS & Self-Managed
Audit eventsPremiumDedicated, SaaS & Self-Managed
Log systemPremiumSelf-Managed
Incident managementPremiumDedicated, SaaS & Self-Managed
AlertsPremiumDedicated, SaaS & Self-Managed
Monitor GitLab with PrometheusPremiumSelf-Managed
Application securityUltimateDedicated, SaaS & Self-Managed
Compliance reportsUltimateDedicated, SaaS & Self-Managed
Security dashboardUltimateDedicated, SaaS & Self-Managed
Vulnerability reportsUltimateDedicated, SaaS & Self-Managed
Vulnerability pagesUltimateDedicated, SaaS & Self-Managed
Vulnerability severity levelsUltimateDedicated, SaaS & Self-Managed
Dependency listUltimateDedicated, SaaS & Self-Managed
Credentials inventoryUltimateSelf-Managed

Data backup

GitLab provides backup and restore procedures to ensure your data is not lost.

SolutionTierDedicated / SaaS / Self-Managed
Backup and restore GitLabPremiumSelf-Managed
Encrypted system configurationPremiumSelf-Managed
SSL configurationPremiumSelf-Managed
PostgreSQL replication and failoverPremiumSelf-Managed
Audit event streamingUltimateDedicated, SaaS & Self-Managed

Change management

GitLab makes it easy to define and enforce policies for all software changes while maintaining a record of what was changed, when it was changed, and who changed it.

SolutionTierDedicated, SaaS / Self-Managed
MR approval rulesPremiumDedicated, SaaS & Self-Managed
Push rulesPremiumDedicated, SaaS & Self-Managed
Code ownersPremiumDedicated, SaaS & Self-Managed
Enable delayed project deletionPremiumDedicated, SaaS & Self-Managed
View description of change historyPremiumDedicated, SaaS & Self-Managed
Security policiesUltimateDedicated, SaaS & Self-Managed
MR security approvalsUltimateDedicated, SaaS & Self-Managed
Requirements managementUltimateDedicated, SaaS & Self-Managed
Status checksUltimateDedicated, SaaS & Self-Managed
License approval policiesUltimateDedicated, SaaS & Self-Managed

Compliance Resources

Start shipping better software faster

See what your team can do with the intelligent

DevSecOps platform.