[{"data":1,"prerenderedAt":1136},["ShallowReactive",2],{"/gitlab-security-standard":3,"navigation-en-us":434,"banner-en-us":865,"footer-en-us":875},{"id":4,"title":5,"body":6,"category":6,"config":6,"content":7,"description":6,"extension":426,"meta":427,"navigation":74,"path":428,"seo":429,"slug":6,"stem":432,"testContent":6,"type":6,"__hash__":433},"pages/en-us/gitlab-security-standard.yml","Gitlab Security Standard",null,[8,17,47,119,140,319,370,413],{"componentName":9,"componentContent":10},"SecurityOneHero",{"eyebrow":11,"title":12,"description":13,"version":14},"Securing your software factory","The GitLab Security\\\nStandard","Organizations are transitioning to a world where agents build software without a human in every step. The GitLab Security Standard shows how to get there securely: security fundamentals that harden the software factory, and stages that let agents earn autonomy.",{"label":15,"text":16},"v1.0","Published October 6, 2026",{"componentName":18,"componentContent":19},"SecurityOneJumpNav",{"label":20,"items":21},"On this page",[22,29,35,41],{"number":23,"text":24,"config":25},"01","The economics have changed",{"href":26,"dataGaName":27,"dataGaLocation":28},"#economics","economics","jump nav",{"number":30,"text":31,"config":32},"02","Trust your agents",{"href":33,"dataGaName":34,"dataGaLocation":28},"#agents","trust your agents",{"number":36,"text":37,"config":38},"03","Framework alignment",{"href":39,"dataGaName":40,"dataGaLocation":28},"#framework-alignment","framework alignment",{"number":42,"text":43,"config":44},"04","Earn autonomy",{"href":45,"dataGaName":46,"dataGaLocation":28},"#earned-autonomy","earn autonomy",{"componentName":48,"componentContent":49},"SecurityOneStatPanel",{"number":23,"title":50,"lede":51,"sourceLabel":52,"cards":53,"config":118},"The economics\nhave changed","**Code is abundant. Trust is scarce.** The same AI models that let agents write and ship code at machine speed also make existing weaknesses faster and cheaper to discover, connect, and exploit. Discovery volume is now rising faster than teams can verify, prioritize, and remediate what matters.","Source",[54,80,99],{"eyebrow":55,"value":56,"description":57,"bars":58,"source":75},"Code is surging","+500%","codebase size growth across GitLab's customer base",[59,64,69],{"label":60,"value":61,"config":62},"Pipelines","+40%",{"percent":63},8,{"label":65,"value":66,"config":67},"Code pushes","+50%",{"percent":68},10,{"label":70,"value":71,"config":72},"Codebase size","up to +500%",{"percent":73,"highlight":74},100,true,{"text":76,"config":77},"GitLab, “Git was built for humans,” Aug. 2026",{"href":78,"dataGaName":79,"dataGaLocation":27},"/blog/gitlab-next-gen-scm/","git was built for humans",{"eyebrow":81,"value":82,"description":83,"bars":84,"source":94},"Vulnerabilities are surging","+46%","more CVEs disclosed through April than FIRST projected, putting 2026 on pace for ~66,000",[85,90],{"label":86,"value":87,"config":88},"Feb forecast","59,427",{"percent":89},90,{"label":91,"value":92,"config":93},"June forecast","~66,000",{"percent":73,"highlight":74},{"text":95,"config":96},"FIRST 2026 Mid-Year Vulnerability Forecast, June 2026",{"href":97,"dataGaName":98,"dataGaLocation":27},"https://www.first.org/newsroom/releases/20260615","first vulnerability forecast",{"eyebrow":100,"value":101,"description":102,"bars":103,"source":113},"Fixes can't keep up","+11 days","longer median time to patch known-exploited vulnerabilities, now 43 days",[104,109],{"label":105,"value":106,"config":107},"2025 report","32",{"percent":108},74.4,{"label":110,"value":111,"config":112},"2026 report","43",{"percent":73,"highlight":74},{"text":114,"config":115},"Verizon 2026 Data Breach Investigations Report",{"href":116,"dataGaName":117,"dataGaLocation":27},"https://www.verizon.com/business/resources/reports/dbir/","verizon dbir",{"id":27},{"componentName":120,"componentContent":121},"SecurityOneStageLoop",{"number":30,"title":122,"intro":123,"pyramid":124,"config":135},"Trust your\nagents","Our approach to building trust in a fleet of agents starts with the software factory they work in. Security is embedded at every stage, so agents operate under controls they can't bypass, and autonomy isn't given. It's earned, one stage at a time.\n\nFive stages, built on a foundation of policy, audit, and ownership, define what every agent must prove. The more an agent proves, the more autonomy it earns.",{"peak":125,"foundation":126,"loop":127,"description":128,"stages":129},"Autonomy","Policy · Audit · Ownership","Find, fix, and learn","Pyramid of five stages, Authorize, Isolate, Verify, Release, and Respond, on a base of policy, audit, and ownership, with autonomy at the top and a find, fix, and learn loop that returns failures to the base.",[130,131,132,133,134],"Authorize","Isolate","Verify","Release","Respond",{"id":136,"failures":137},"agents",[138,139],1,3,{"componentName":141,"componentContent":142},"SecurityOneStages",{"labels":143,"foundation":146,"stages":160,"loop":305},{"purpose":144,"controls":145},"Purpose","Example controls",{"eyebrow":147,"title":148,"description":149,"items":150},"Foundation · Where trust starts","Policy, Audit, Ownership","Rules to enforce, a record of what happened, and a named human accountable when they fail. Without the foundation, no stage can be proven.",[151,154,157],{"title":152,"text":153},"Policy","Humans define what agents can and can't do: which tools they use, what they can touch, and which actions need approval. Those policies are defined and approved before any code is written, then enforced automatically.",{"title":155,"text":156},"Audit","An immutable audit trail of every agent and model, down to each prompt, reasoning step, tool call, and action, linked from task to deployment.",{"title":158,"text":159},"Ownership","Every agent, service account, and control is accountable to a named human.",[161,190,218,247,276],{"name":130,"purpose":162,"definition":163,"controls":164},"Who and what can act, and within what limits?","Every person, agent, and service has a known or composite identity, a named owner, and access scoped to the task at hand.",[165,174,182],{"title":166,"text":167,"feature":168},"Agent inventory","Every agent, integration, and service account is known, with an owner",{"text":169,"config":170},"AI Catalog",{"href":171,"dataGaName":172,"dataGaLocation":173},"https://docs.gitlab.com/user/duo_agent_platform/ai_catalog/","ai catalog","authorize",{"title":175,"text":176,"feature":177},"Agent identity","Every agent action traces to the agent and the human who triggered it",{"text":178,"config":179},"Composite identity",{"href":180,"dataGaName":181,"dataGaLocation":173},"https://docs.gitlab.com/user/duo_agent_platform/composite_identity/","composite identity",{"title":183,"text":184,"feature":185},"Secrets management","Centralized, least privilege, rotated, and revocable, with a defined scope and lifetime for every credential",{"text":186,"config":187},"GitLab Secrets Manager",{"href":188,"dataGaName":189,"dataGaLocation":173},"https://docs.gitlab.com/ci/secrets/secrets_manager/","secrets manager",{"name":131,"purpose":191,"definition":192,"controls":193},"Can a compromised input or tool reach beyond the task?","Work runs in a contained environment whose boundaries hold even when the agent follows a malicious instruction.",[194,203,209],{"title":195,"text":196,"feature":197},"Isolated execution","Ephemeral workspace with restricted storage and network",{"text":198,"config":199},"Duo Agent Platform execution environment",{"href":200,"dataGaName":201,"dataGaLocation":202},"https://docs.gitlab.com/user/duo_agent_platform/flows/execution/","execution environment","isolate",{"title":204,"text":205,"feature":206},"Trusted dependencies","Packages are pulled through a controlled proxy and checked before they reach the build",{"text":207,"badge":208},"Dependency Firewall","Closed beta",{"title":210,"text":211,"feature":212},"Sanctioned tools and access paths","Agents use only approved tools, connections, and MCP servers",{"text":213,"badge":214,"config":215},"AI Governance","Beta",{"href":216,"dataGaName":217,"dataGaLocation":202},"https://docs.gitlab.com/user/ai-governance/tool-governance/","ai governance",{"name":132,"purpose":219,"definition":220,"controls":221},"Is the change safe, checked by controls the actor cannot touch?","Every change, human or agent, passes security checks that are centrally enforced and that cannot be modified or waived.",[222,231,239],{"title":223,"text":224,"feature":225},"Policy in the execution path","Scans, approvals, and deployment controls are enforced centrally, not per project",{"text":226,"config":227},"Pipeline execution policies",{"href":228,"dataGaName":229,"dataGaLocation":230},"https://docs.gitlab.com/user/application_security/policies/pipeline_execution_policies/","pipeline execution policies","verify",{"title":232,"text":233,"feature":234},"Protected checks","The actor cannot edit the pipeline or policy that judges it",{"text":235,"config":236},"Protected branches",{"href":237,"dataGaName":238,"dataGaLocation":230},"https://docs.gitlab.com/user/project/repository/branches/protected/","protected branches",{"title":240,"text":241,"feature":242},"Separation of duties","The author, human or agent, cannot be the sole approver",{"text":243,"config":244},"Merge request approval policies",{"href":245,"dataGaName":246,"dataGaLocation":230},"https://docs.gitlab.com/user/application_security/policies/merge_request_approval_policies/","merge request approval policies",{"name":133,"purpose":248,"definition":249,"controls":250},"Does production get exactly what was verified?","Deployment decisions bind to the exact artifact that passed verification, identified by digest and provenance, not by name or version label.",[251,260,268],{"title":252,"text":253,"feature":254},"Provenance and signing","Every artifact carries signed evidence of source, inputs, and build",{"text":255,"config":256},"SLSA provenance generation",{"href":257,"dataGaName":258,"dataGaLocation":259},"https://docs.gitlab.com/ci/pipeline_security/slsa/","slsa provenance","release",{"title":261,"text":262,"feature":263},"Verify before deploy","The deployed digest must match the approved one",{"text":264,"config":265},"Artifact attestation verification",{"href":266,"dataGaName":267,"dataGaLocation":259},"https://docs.gitlab.com/cli/attestation/verify/","artifact attestation verification",{"title":269,"text":270,"feature":271},"Immutable references","Tags and images cannot be overwritten after approval",{"text":272,"config":273},"Protected container tags",{"href":274,"dataGaName":275,"dataGaLocation":259},"https://docs.gitlab.com/user/packages/container_registry/protected_container_tags/","protected container tags",{"name":134,"purpose":277,"definition":278,"controls":279},"Can we stop it, trace it, and recover?","Suspicious activity and vulnerable output connect to a response that can stop the task, trace what it touched, and verify the fix.",[280,289,297],{"title":281,"text":282,"feature":283},"Tested kill switch","Stop a task, revoke its access, pause releases",{"text":284,"config":285},"Service account blocking",{"href":286,"dataGaName":287,"dataGaLocation":288},"https://docs.gitlab.com/user/profile/service_accounts/","service account blocking","respond",{"title":290,"text":291,"feature":292},"Trace impact","Identify every change and release an agent touched",{"text":293,"config":294},"Audit events",{"href":295,"dataGaName":296,"dataGaLocation":288},"https://docs.gitlab.com/user/compliance/audit_events/","audit events",{"title":298,"text":299,"feature":300},"Monitor consequential actions","Tool use, credential access, permission changes, and deployments are visible",{"text":301,"config":302},"Audit event streaming",{"href":303,"dataGaName":304,"dataGaLocation":288},"https://docs.gitlab.com/user/compliance/audit_event_streaming/","audit event streaming",{"eyebrow":306,"title":127,"text":307,"link":308,"metrics":314},"The feedback loop","When something fails, learn from it and update the policy, so the rules improve before autonomy is restored.\n\nAt the same time, security agents continuously detect, triage, and remediate vulnerabilities.",{"text":309,"config":310},"Automated remediation",{"href":311,"dataGaName":312,"dataGaLocation":313},"https://docs.gitlab.com/user/application_security/vulnerabilities/agentic_vulnerability_resolution/","automated remediation","feedback loop",{"label":315,"items":316},"What we measure",[317,318],"Time to containment","Time to verified remediation",{"componentName":320,"componentContent":321},"SecurityOneFrameworkTable",{"number":36,"title":322,"description":323,"columns":324,"rows":330,"footnote":367,"config":368},"Framework\nalignment","The standard maps to the frameworks your security and compliance teams already report on.",[325,326,327,328,329],"Stage","[OWASP SAMM](https://owaspsamm.org/model/){data-ga-name=\"owasp samm\" data-ga-location=\"framework alignment\"}","[OWASP Top 10 for Agentic Applications](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/){data-ga-name=\"owasp agentic top 10\" data-ga-location=\"framework alignment\"}","[MITRE ATLAS](https://atlas.mitre.org/){data-ga-name=\"mitre atlas\" data-ga-location=\"framework alignment\"}","NIST [SSDF](https://csrc.nist.gov/pubs/sp/800/218/final){data-ga-name=\"nist ssdf\" data-ga-location=\"framework alignment\"} & [SP 800-53](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final){data-ga-name=\"nist sp 800-53\" data-ga-location=\"framework alignment\"}",[331,338,344,350,355,361],{"stage":332,"subtitle":148,"cells":333},"Foundation",[334,335,336,337],"- [Policy & Compliance](https://owaspsamm.org/model/governance/policy-and-compliance/){data-ga-name=\"samm policy and compliance\" data-ga-location=\"framework alignment\"}\n- [Strategy & Metrics](https://owaspsamm.org/model/governance/strategy-and-metrics/){data-ga-name=\"samm strategy and metrics\" data-ga-location=\"framework alignment\"}\n- [Security Requirements](https://owaspsamm.org/model/design/security-requirements/){data-ga-name=\"samm security requirements\" data-ga-location=\"framework alignment\"}","- Least agency (core principle)","","- SSDF PO.1, PO.2, PO.3\n- SP 800-53 AU",{"stage":130,"number":23,"cells":339},[340,341,342,343],"- [Secure Deployment](https://owaspsamm.org/model/implementation/secure-deployment/){data-ga-name=\"samm secure deployment\" data-ga-location=\"framework alignment\"}","- ASI03 Identity and Privilege Abuse\n- ASI07 Insecure Inter-Agent Communication\n- ASI10 Rogue Agents","- [AI Agent Tool Credential Harvesting (AML.T0098)](https://atlas.mitre.org/techniques/AML.T0098){data-ga-name=\"atlas aml.t0098\" data-ga-location=\"framework alignment\"}\n- [Exfiltration via AI Agent Tool Invocation (AML.T0086)](https://atlas.mitre.org/techniques/AML.T0086){data-ga-name=\"atlas aml.t0086\" data-ga-location=\"framework alignment\"}","- SSDF PS.1\n- SP 800-53 AC-2, AC-5, AC-6, CM-3, CM-5, IA, SA-11",{"stage":131,"number":30,"cells":345},[346,347,348,349],"- [Secure Architecture](https://owaspsamm.org/model/design/secure-architecture/){data-ga-name=\"samm secure architecture\" data-ga-location=\"framework alignment\"}\n- [Secure Build](https://owaspsamm.org/model/implementation/secure-build/){data-ga-name=\"samm secure build\" data-ga-location=\"framework alignment\"}\n- [Environment Management](https://owaspsamm.org/model/operations/environment-management/){data-ga-name=\"samm environment management\" data-ga-location=\"framework alignment\"}","- ASI01 Agent Goal Hijack\n- ASI02 Tool Misuse and Exploitation\n- ASI04 Agentic Supply Chain Vulnerabilities\n- ASI05 Unexpected Code Execution\n- ASI06 Memory and Context Poisoning\n- ASI08 Cascading Failures","- [LLM Prompt Injection (AML.T0051)](https://atlas.mitre.org/techniques/AML.T0051){data-ga-name=\"atlas aml.t0051\" data-ga-location=\"framework alignment\"}\n- [AI Agent Tool Poisoning (AML.T0110)](https://atlas.mitre.org/techniques/AML.T0110){data-ga-name=\"atlas aml.t0110\" data-ga-location=\"framework alignment\"}\n- [AI Supply Chain Compromise (AML.T0010)](https://atlas.mitre.org/techniques/AML.T0010){data-ga-name=\"atlas aml.t0010\" data-ga-location=\"framework alignment\"}","- SSDF PO.5, PW.4\n- SP 800-53 SC-7, SC-39, SR",{"stage":132,"number":36,"cells":351},[352,353,336,354],"- [Security Testing](https://owaspsamm.org/model/verification/security-testing/){data-ga-name=\"samm security testing\" data-ga-location=\"framework alignment\"}\n- [Requirements-driven Testing](https://owaspsamm.org/model/verification/requirements-driven-testing/){data-ga-name=\"samm requirements-driven testing\" data-ga-location=\"framework alignment\"}\n- [Defect Management](https://owaspsamm.org/model/implementation/defect-management/){data-ga-name=\"samm defect management\" data-ga-location=\"framework alignment\"}","- ASI05 Unexpected Code Execution\n- ASI09 Human-Agent Trust Exploitation","- SSDF PO.4, PW.7, PW.8",{"stage":133,"number":42,"cells":356},[357,358,359,360],"- [Secure Build](https://owaspsamm.org/model/implementation/secure-build/){data-ga-name=\"samm secure build\" data-ga-location=\"framework alignment\"}\n- [Secure Deployment](https://owaspsamm.org/model/implementation/secure-deployment/){data-ga-name=\"samm secure deployment\" data-ga-location=\"framework alignment\"}","- ASI04 Agentic Supply Chain Vulnerabilities","- [AI Supply Chain Compromise (AML.T0010)](https://atlas.mitre.org/techniques/AML.T0010){data-ga-name=\"atlas aml.t0010\" data-ga-location=\"framework alignment\"}","- SSDF PS.2, PS.3\n- SP 800-53 SI-7, SR-4",{"stage":134,"number":362,"cells":363},"05",[364,365,336,366],"- [Incident Management](https://owaspsamm.org/model/operations/incident-management/){data-ga-name=\"samm incident management\" data-ga-location=\"framework alignment\"}","- ASI10 Rogue Agents","- SSDF RV.1 to RV.3\n- SP 800-53 IR, AU","MITRE ATLAS catalogs adversary techniques against AI systems, so not every stage has a direct match.",{"id":369},"framework-alignment",{"componentName":371,"componentContent":372},"SecurityOneAutonomyLevels",{"number":42,"title":373,"description":374,"pyramid":375,"levels":377,"config":411},"Earned\nautonomy","Autonomy is granted per workflow, and each workflow must pass every stage's tests before it earns more. Different workflows can operate at different levels of autonomy at the same time.",{"peak":125,"foundation":126,"stages":376},[130,131,132,133,134],[378,390,400],{"label":379,"title":380,"proven":381,"details":382,"config":389},"Level 1","Suggest","Proven: Foundation + Authorize",[383,386],{"label":384,"text":385},"What the agent may do","Recommend; humans make the change",{"label":387,"text":388},"Example workflow","Pipeline and policy config (changes to the controls themselves)",{"reach":138},{"label":391,"title":392,"proven":393,"details":394,"config":399},"Level 2","Propose","Proven: Foundation + Authorize through Verify",[395,397],{"label":384,"text":396},"Open the MR; a human approves release",{"label":387,"text":398},"Application security fixes",{"reach":139},{"label":401,"title":402,"proven":403,"details":404,"config":409},"Level 3","Act with guardrails","Proven: Foundation + all five stages, including a tested stop",[405,407],{"label":384,"text":406},"Fix, test, and merge; humans review by exception; volume and blast-radius caps apply",{"label":387,"text":408},"Dependency updates for reachable, known-exploited vulnerabilities",{"reach":410},5,{"id":412},"earned-autonomy",{"componentName":414,"componentContent":415},"SecurityOneCta",{"title":416,"description":417,"form":418,"note":423,"config":424},"Have your\nagents earned\nautonomy?","Request your free assessment on how to earn the next level of autonomy in your environment.",{"config":419,"submitButtonText":422},{"formId":420,"formName":421,"skeletonFieldCount":63},1002,"resources","Sign up today","GitLab runs this standard against its own software factory. It's public, ungated, and always evolving. As threats, models, and our own capabilities change, we'll keep updating it and show what changed.",{"id":425},"assessment","yml",{},"/en-us/gitlab-security-standard",{"title":430,"description":431},"The GitLab Security Standard: Securing your software factory","Security fundamentals that harden the software factory, and stages that let agents earn autonomy as they build software without a human in every step.","en-us/gitlab-security-standard","VG7hsWj9FBTUWWKpWg9gQQgqODSWYysd22YddRXKNkM",{"logo":435,"freeTrial":440,"sales":445,"login":450,"items":455,"search":785,"minimal":816,"duo":835,"switchNav":844,"pricingDeployment":855},{"config":436},{"href":437,"dataGaName":438,"dataGaLocation":439},"/","gitlab logo","header",{"text":441,"config":442},"Get free trial",{"href":443,"dataGaName":444,"dataGaLocation":439},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com&glm_content=default-saas-trial/","free trial",{"text":446,"config":447},"Request a demo",{"href":448,"dataGaName":449,"dataGaLocation":439},"/request-a-demo/","sales",{"text":451,"config":452},"Sign in",{"href":453,"dataGaName":454,"dataGaLocation":439},"https://gitlab.com/users/sign_in/","sign in",[456,542,630,635,709,763],{"text":457,"left":74,"config":458,"menu":460},"Platform",{"dataNavLevelOne":459},"platform",{"type":461,"link":462,"columns":466,"feature":531},"lists",{"text":463,"config":464},"Explore the Platform",{"href":465,"dataGaName":459,"dataGaLocation":439},"/platform/",[467,490,513],{"title":468,"items":469},"Execution & Workflows",[470,475,480,485],{"text":471,"config":472},"CI/CD",{"href":473,"dataGaLocation":439,"dataGaName":474},"/solutions/continuous-integration/","ci/cd",{"text":476,"config":477},"Source Code Management",{"href":478,"dataGaLocation":439,"dataGaName":479},"/solutions/source-code-management/","source code management",{"text":481,"config":482},"Agile Delivery",{"href":483,"dataGaLocation":439,"dataGaName":484},"/solutions/agile-delivery/","agile delivery",{"text":486,"config":487},"Artifact Management",{"href":488,"dataGaLocation":439,"dataGaName":489},"/artifact-central/","artifact management",{"title":491,"items":492},"Security & Governance",[493,498,503,508],{"text":494,"config":495},"Application Security Testing",{"href":496,"dataGaLocation":439,"dataGaName":497},"/solutions/application-security-testing/","application security testing",{"text":499,"config":500},"Governance & Compliance",{"href":501,"dataGaLocation":439,"dataGaName":502},"/solutions/software-compliance/","governance and compliance",{"text":504,"config":505},"Secrets Management",{"href":506,"dataGaLocation":439,"dataGaName":507},"/gitlab-secrets-manager/","secrets management",{"text":509,"config":510},"Supply Chain Security",{"href":511,"dataGaLocation":439,"dataGaName":512},"/solutions/supply-chain/","supply chain security",{"title":514,"items":515},"Context & AI",[516,521,526],{"text":517,"config":518},"Agentic Orchestration",{"href":519,"dataGaLocation":439,"dataGaName":520},"/gitlab-duo-agent-platform/","agentic orchestration",{"text":522,"config":523},"Context Graph",{"href":524,"dataGaLocation":439,"dataGaName":525},"/gitlab-orbit/","context graph",{"text":527,"config":528},"Visibility & Measurement",{"href":529,"dataGaLocation":439,"dataGaName":530},"/solutions/visibility-measurement/","visibility and measurement",{"config":532,"title":535,"text":536,"link":537},{"background":533,"textColor":534},"url('https://res.cloudinary.com/about-gitlab-com/image/upload/v1790185102/o7dn32anqcb6z8dgd3as.jpg')","#000","Why GitLab","One platform for speed with control across your software lifecycle.",{"text":538,"config":539},"Learn more",{"href":540,"dataGaName":541,"dataGaLocation":439},"/why-gitlab/","why gitlab",{"text":543,"left":74,"config":544,"menu":546},"Solutions",{"dataNavLevelOne":545},"solutions",{"type":461,"link":547,"columns":551,"feature":621},{"text":548,"config":549},"View all Solutions",{"href":550,"dataGaName":545,"dataGaLocation":439},"/solutions/",[552,570,588],{"title":553,"items":554},"Outcomes",[555,560,565],{"text":556,"config":557},"DevOps Modernization",{"href":558,"dataGaLocation":439,"dataGaName":559},"/assessments/devops-modernization-assessment/","devops modernization",{"text":561,"config":562},"Security Modernization",{"href":563,"dataGaLocation":439,"dataGaName":564},"/assessments/security-modernization-assessment/","security modernization",{"text":566,"config":567},"AI Modernization",{"href":568,"dataGaLocation":439,"dataGaName":569},"/assessments/ai-modernization-assessment/","ai modernization",{"title":571,"items":572},"By size",[573,578,583],{"text":574,"config":575},"Enterprise",{"href":576,"dataGaLocation":439,"dataGaName":577},"/enterprise/","enterprise",{"text":579,"config":580},"Small Business",{"href":581,"dataGaLocation":439,"dataGaName":582},"/small-business/","small business",{"text":584,"config":585},"Startups",{"href":586,"dataGaLocation":439,"dataGaName":587},"/solutions/startups/","startups",{"title":589,"items":590},"Industries",[591,596,601,606,611,616],{"text":592,"config":593},"Financial Services",{"href":594,"dataGaLocation":439,"dataGaName":595},"/solutions/finance/","financial services",{"text":597,"config":598},"Public Sector",{"href":599,"dataGaLocation":439,"dataGaName":600},"/solutions/public-sector/","public sector",{"text":602,"config":603},"Telecommunications",{"href":604,"dataGaLocation":439,"dataGaName":605},"/solutions/telecommunications/","telecommunications",{"text":607,"config":608},"Automotive",{"href":609,"dataGaLocation":439,"dataGaName":610},"/solutions/automotive/","automotive",{"text":612,"config":613},"Education",{"href":614,"dataGaLocation":439,"dataGaName":615},"/solutions/education/","education",{"text":617,"config":618},"Aerospace",{"href":619,"dataGaLocation":439,"dataGaName":620},"/solutions/aerospace/","aerospace",{"config":622,"title":623,"text":624,"link":625},{"background":533,"textColor":534},"GitLab Security Standard","Learn how to harden your software factory and let AI agents earn autonomy, without trading away security.",{"text":626,"config":627},"Explore the standard",{"href":628,"dataGaName":629,"dataGaLocation":439},"/gitlab-security-standard/","gitlab security standard",{"text":631,"config":632},"Pricing",{"href":633,"dataGaName":634,"dataGaLocation":439,"dataNavLevelOne":634},"/pricing/","pricing",{"text":636,"config":637,"menu":638},"Resources",{"dataNavLevelOne":421},{"type":461,"link":639,"columns":643,"feature":700},{"text":640,"config":641},"View all resources",{"href":642,"dataGaName":421,"dataGaLocation":439},"/resources/",[644,672],{"title":645,"items":646},"Discover",[647,652,657,662,667],{"text":648,"config":649},"Docs",{"href":650,"dataGaName":651,"dataGaLocation":439},"https://docs.gitlab.com/","docs",{"text":653,"config":654},"University",{"href":655,"dataGaName":656,"dataGaLocation":439},"https://university.gitlab.com/","university",{"text":658,"config":659},"Demo Series",{"href":660,"dataGaName":661,"dataGaLocation":439},"/gitlab-technical-demo-series/","demo series",{"text":663,"config":664},"Demo Hub",{"href":665,"dataGaName":666,"dataGaLocation":439},"/demo-hub/","demo hub",{"text":668,"config":669},"Services",{"href":670,"dataGaName":671,"dataGaLocation":439},"/services/","services",{"title":673,"items":674},"Connect",[675,680,685,690,695],{"text":676,"config":677},"Blog",{"href":678,"dataGaName":679,"dataGaLocation":439},"/blog/","blog",{"text":681,"config":682},"Community",{"href":683,"dataGaName":684,"dataGaLocation":439},"/community/","community",{"text":686,"config":687},"Customers",{"href":688,"dataGaName":689,"dataGaLocation":439},"/customers/","customers",{"text":691,"config":692},"Partners",{"href":693,"dataGaName":694,"dataGaLocation":439},"/partners/","partners",{"text":696,"config":697},"Events",{"href":698,"dataGaName":699,"dataGaLocation":439},"/events/","events",{"config":701,"title":702,"text":703,"link":704},{"background":533,"textColor":534},"What’s new in GitLab","Stay updated with our latest features and improvements.",{"text":705,"config":706},"Read the latest",{"href":707,"dataGaName":708,"dataGaLocation":439},"/whats-new/","whats new",{"text":710,"config":711,"menu":713},"Company",{"dataNavLevelOne":712},"company",{"type":461,"columns":714},[715],{"items":716},[717,722,728,733,738,743,748,753,758],{"text":718,"config":719},"About",{"href":720,"dataGaName":721,"dataGaLocation":439},"/company/","about",{"text":723,"config":724,"footerGa":727},"Jobs",{"href":725,"dataGaName":726,"dataGaLocation":439},"/jobs/","jobs",{"dataGaName":726},{"text":729,"config":730},"Press",{"href":731,"dataGaName":732,"dataGaLocation":439},"/press/","press",{"text":734,"config":735},"Handbook",{"href":736,"dataGaName":737,"dataGaLocation":439},"https://handbook.gitlab.com/","handbook",{"text":739,"config":740},"Leadership",{"href":741,"dataGaName":742,"dataGaLocation":439},"/company/team/e-group/","leadership",{"text":744,"config":745},"Investor relations",{"href":746,"dataGaName":747,"dataGaLocation":439},"https://ir.gitlab.com/overview/default.aspx","investor relations",{"text":749,"config":750},"Trust Center",{"href":751,"dataGaName":752,"dataGaLocation":439},"/security/","trust center",{"text":754,"config":755},"AI Transparency Center",{"href":756,"dataGaName":757,"dataGaLocation":439},"/ai-transparency-center/","ai transparency center",{"text":759,"config":760},"Newsletter",{"href":761,"dataGaName":762,"dataGaLocation":439},"/company/contact/#contact-forms","newsletter",{"text":764,"config":765,"menu":766},"Contact us",{"dataNavLevelOne":712},{"type":461,"columns":767},[768],{"items":769},[770,775,780],{"text":771,"config":772},"Talk to sales",{"href":773,"dataGaName":774,"dataGaLocation":439},"/sales/","talk to sales",{"text":776,"config":777},"Support portal",{"href":778,"dataGaName":779,"dataGaLocation":439},"https://support.gitlab.com/hc/en-us","support portal",{"text":781,"config":782},"Customer portal",{"href":783,"dataGaName":784,"dataGaLocation":439},"https://customers.gitlab.com/customers/sign_in/","customer portal",{"close":786,"login":787,"suggestions":794},"Close",{"text":788,"link":789},"To search repositories and projects, login to",{"text":790,"config":791},"gitlab.com",{"href":453,"dataGaName":792,"dataGaLocation":793},"search login","search",{"text":795,"default":796},"Suggestions",[797,800,803,805,809,813],{"text":798,"config":799},"GitLab Duo Agent Platform",{"href":519,"dataGaName":798,"dataGaLocation":793},{"text":801,"config":802},"Code Suggestions (AI)",{"href":519,"dataGaName":801,"dataGaLocation":793},{"text":471,"config":804},{"href":473,"dataGaName":471,"dataGaLocation":793},{"text":806,"config":807},"GitLab on AWS",{"href":808,"dataGaName":806,"dataGaLocation":793},"/partners/technology-partners/aws/",{"text":810,"config":811},"GitLab on Google Cloud",{"href":812,"dataGaName":810,"dataGaLocation":793},"/partners/technology-partners/google-cloud-platform/",{"text":814,"config":815},"Why GitLab?",{"href":540,"dataGaName":814,"dataGaLocation":793},{"freeTrial":817,"mobileIcon":822,"desktopIcon":827,"secondaryButton":830},{"text":818,"config":819},"Start free trial",{"href":820,"dataGaName":444,"dataGaLocation":821},"https://gitlab.com/-/trials/new/","nav",{"altText":823,"config":824},"Gitlab Icon",{"src":825,"dataGaName":826,"dataGaLocation":821},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203874/jypbw1jx72aexsoohd7x.svg","gitlab icon",{"altText":823,"config":828},{"src":829,"dataGaName":826,"dataGaLocation":821},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1758203875/gs4c8p8opsgvflgkswz9.svg",{"text":831,"config":832},"Get Started",{"href":833,"dataGaName":834,"dataGaLocation":821},"https://gitlab.com/-/trial_registrations/new?glm_source=about.gitlab.com/get-started/","get started",{"freeTrial":836,"mobileIcon":840,"desktopIcon":842},{"text":837,"config":838},"Learn more about GitLab Duo",{"href":519,"dataGaName":839,"dataGaLocation":821},"gitlab duo",{"altText":823,"config":841},{"src":825,"dataGaName":826,"dataGaLocation":821},{"altText":823,"config":843},{"src":829,"dataGaName":826,"dataGaLocation":821},{"button":845,"mobileIcon":850,"desktopIcon":852},{"text":846,"config":847},"/switch",{"href":848,"dataGaName":849,"dataGaLocation":821},"#contact","switch",{"altText":823,"config":851},{"src":825,"dataGaName":826,"dataGaLocation":821},{"altText":823,"config":853},{"src":854,"dataGaName":826,"dataGaLocation":821},"https://res.cloudinary.com/about-gitlab-com/image/upload/v1773335277/ohhpiuoxoldryzrnhfrh.png",{"freeTrial":856,"mobileIcon":861,"desktopIcon":863},{"text":857,"config":858},"Back to pricing",{"href":633,"dataGaName":859,"dataGaLocation":821,"icon":860},"back to pricing","GoBack",{"altText":823,"config":862},{"src":825,"dataGaName":826,"dataGaLocation":821},{"altText":823,"config":864},{"src":829,"dataGaName":826,"dataGaLocation":821},{"title":866,"button":867,"config":873},"Ship at agent speed. Prove every step. Transcend returns on October 6.",{"text":868,"config":869},"Register now",{"href":870,"dataGaName":871,"dataGaLocation":872},"/events/transcend/virtual/#register","transcend-october-2026-banner","global-banner",{"layout":259,"disabled":874},false,{"data":876},{"text":877,"source":878,"edit":884,"contribute":889,"config":894,"items":899,"minimal":1125},"Git is a trademark of Software Freedom Conservancy and our use of 'GitLab' is under license",{"text":879,"config":880},"View page source",{"href":881,"dataGaName":882,"dataGaLocation":883},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/","page source","footer",{"text":885,"config":886},"Edit this page",{"href":887,"dataGaName":888,"dataGaLocation":883},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/content/","web ide",{"text":890,"config":891},"Please contribute",{"href":892,"dataGaName":893,"dataGaLocation":883},"https://gitlab.com/gitlab-com/marketing/digital-experience/about-gitlab-com/-/blob/main/CONTRIBUTING.md/","please contribute",{"twitter":895,"facebook":896,"youtube":897,"linkedin":898},"https://twitter.com/gitlab","https://www.facebook.com/gitlab","https://www.youtube.com/channel/UCnMGQ8QHMAnVIsI3xJrihhg","https://www.linkedin.com/company/gitlab-com",[900,947,1005,1052,1093],{"title":631,"links":901,"subMenu":916},[902,906,911],{"text":903,"config":904},"View plans",{"href":633,"dataGaName":905,"dataGaLocation":883},"view plans",{"text":907,"config":908},"Why Premium?",{"href":909,"dataGaName":910,"dataGaLocation":883},"/pricing/premium/","why premium",{"text":912,"config":913},"Why Ultimate?",{"href":914,"dataGaName":915,"dataGaLocation":883},"/pricing/ultimate/","why ultimate",[917],{"title":918,"links":919},"Contact Us",[920,923,925,927,932,937,942],{"text":921,"config":922},"Contact sales",{"href":773,"dataGaName":449,"dataGaLocation":883},{"text":776,"config":924},{"href":778,"dataGaName":779,"dataGaLocation":883},{"text":781,"config":926},{"href":783,"dataGaName":784,"dataGaLocation":883},{"text":928,"config":929},"Status",{"href":930,"dataGaName":931,"dataGaLocation":883},"https://status.gitlab.com/","status",{"text":933,"config":934},"Terms of use",{"href":935,"dataGaName":936,"dataGaLocation":883},"/terms/","terms of use",{"text":938,"config":939},"Privacy statement",{"href":940,"dataGaName":941,"dataGaLocation":883},"/privacy/","privacy statement",{"text":943,"config":944},"Cookie preferences",{"dataGaName":945,"dataGaLocation":883,"id":946,"isOneTrustButton":74},"cookie preferences","ot-sdk-btn",{"title":457,"links":948,"subMenu":962},[949,952,954,956,958,960],{"text":950,"config":951},"Explore the platform",{"href":465,"dataGaName":459,"dataGaLocation":883},{"text":517,"config":953},{"href":519,"dataGaName":520,"dataGaLocation":883},{"text":471,"config":955},{"href":473,"dataGaName":474,"dataGaLocation":883},{"text":522,"config":957},{"href":524,"dataGaName":525,"dataGaLocation":883},{"text":504,"config":959},{"href":506,"dataGaName":507,"dataGaLocation":883},{"text":535,"config":961},{"href":540,"dataGaName":541,"dataGaLocation":883},[963],{"title":964,"links":965},"Topics",[966,970,975,980,985,990,995,1000],{"text":471,"config":967},{"href":968,"dataGaName":969,"dataGaLocation":883},"/topics/ci-cd/","cicd",{"text":971,"config":972},"GitOps",{"href":973,"dataGaName":974,"dataGaLocation":883},"/topics/gitops/","gitops",{"text":976,"config":977},"DevOps",{"href":978,"dataGaName":979,"dataGaLocation":883},"/topics/devops/","devops",{"text":981,"config":982},"Version Control",{"href":983,"dataGaName":984,"dataGaLocation":883},"/topics/version-control/","version control",{"text":986,"config":987},"DevSecOps",{"href":988,"dataGaName":989,"dataGaLocation":883},"/topics/devsecops/","devsecops",{"text":991,"config":992},"Cloud Native",{"href":993,"dataGaName":994,"dataGaLocation":883},"/topics/cloud-native/","cloud native",{"text":996,"config":997},"AI for Coding",{"href":998,"dataGaName":999,"dataGaLocation":883},"/topics/devops/ai-for-coding/","ai for coding",{"text":1001,"config":1002},"Agentic AI",{"href":1003,"dataGaName":1004,"dataGaLocation":883},"/topics/agentic-ai/","agentic ai",{"title":543,"links":1006},[1007,1010,1013,1016,1019,1022,1024,1026,1028,1030,1032,1035,1037,1040,1044,1048],{"text":1008,"config":1009},"DevOps modernization",{"href":558,"dataGaName":559,"dataGaLocation":883},{"text":1011,"config":1012},"Security modernization",{"href":563,"dataGaName":564,"dataGaLocation":883},{"text":1014,"config":1015},"AI modernization",{"href":568,"dataGaName":569,"dataGaLocation":883},{"text":1017,"config":1018},"Financial services",{"href":594,"dataGaName":595,"dataGaLocation":883},{"text":1020,"config":1021},"Public sector",{"href":599,"dataGaName":600,"dataGaLocation":883},{"text":602,"config":1023},{"href":604,"dataGaName":605,"dataGaLocation":883},{"text":607,"config":1025},{"href":609,"dataGaName":610,"dataGaLocation":883},{"text":612,"config":1027},{"href":614,"dataGaName":615,"dataGaLocation":883},{"text":617,"config":1029},{"href":619,"dataGaName":620,"dataGaLocation":883},{"text":574,"config":1031},{"href":576,"dataGaName":577,"dataGaLocation":883},{"text":1033,"config":1034},"Small business",{"href":581,"dataGaName":582,"dataGaLocation":883},{"text":584,"config":1036},{"href":586,"dataGaName":587,"dataGaLocation":883},{"text":971,"config":1038},{"href":1039,"dataGaName":974,"dataGaLocation":883},"/solutions/gitops/",{"text":1041,"config":1042},"Software composition analysis",{"href":511,"dataGaName":1043,"dataGaLocation":883},"software composition analysis",{"text":1045,"config":1046},"Value stream management",{"href":529,"dataGaName":1047,"dataGaLocation":883},"value stream management",{"text":1049,"config":1050},"All solutions",{"href":550,"dataGaName":1051,"dataGaLocation":883},"all solutions",{"title":636,"links":1053},[1054,1059,1064,1066,1068,1070,1072,1074,1076,1078,1080,1082,1084,1086,1089],{"text":1055,"config":1056},"Install",{"href":1057,"dataGaName":1058,"dataGaLocation":883},"/install/","install",{"text":1060,"config":1061},"Quick start guides",{"href":1062,"dataGaName":1063,"dataGaLocation":883},"/get-started/","quick setup checklists",{"text":648,"config":1065},{"href":650,"dataGaName":651,"dataGaLocation":883},{"text":653,"config":1067},{"href":655,"dataGaName":656,"dataGaLocation":883},{"text":658,"config":1069},{"href":660,"dataGaName":661,"dataGaLocation":883},{"text":663,"config":1071},{"href":665,"dataGaName":666,"dataGaLocation":883},{"text":668,"config":1073},{"href":670,"dataGaName":671,"dataGaLocation":883},{"text":676,"config":1075},{"href":678,"dataGaName":679,"dataGaLocation":883},{"text":681,"config":1077},{"href":683,"dataGaName":684,"dataGaLocation":883},{"text":686,"config":1079},{"href":688,"dataGaName":689,"dataGaLocation":883},{"text":691,"config":1081},{"href":693,"dataGaName":694,"dataGaLocation":883},{"text":696,"config":1083},{"href":698,"dataGaName":699,"dataGaLocation":883},{"text":759,"config":1085},{"href":761,"dataGaName":762,"dataGaLocation":883},{"text":1087,"config":1088},"What's new",{"href":707,"dataGaName":708,"dataGaLocation":883},{"text":1090,"config":1091},"All resources",{"href":642,"dataGaName":1092,"dataGaLocation":883},"all resources",{"title":710,"links":1094},[1095,1097,1099,1101,1103,1105,1107,1109,1111,1115,1120],{"text":718,"config":1096},{"href":720,"dataGaName":712,"dataGaLocation":883},{"text":723,"config":1098},{"href":725,"dataGaName":726,"dataGaLocation":883},{"text":729,"config":1100},{"href":731,"dataGaName":732,"dataGaLocation":883},{"text":734,"config":1102},{"href":736,"dataGaName":737,"dataGaLocation":883},{"text":739,"config":1104},{"href":741,"dataGaName":742,"dataGaLocation":883},{"text":744,"config":1106},{"href":746,"dataGaName":747,"dataGaLocation":883},{"text":749,"config":1108},{"href":751,"dataGaName":752,"dataGaLocation":883},{"text":754,"config":1110},{"href":756,"dataGaName":757,"dataGaLocation":883},{"text":1112,"config":1113},"Sustainability",{"href":1114,"dataGaName":1112,"dataGaLocation":883},"/sustainability/",{"text":1116,"config":1117},"Diversity, inclusion and belonging (DIB)",{"href":1118,"dataGaName":1119,"dataGaLocation":883},"/diversity-inclusion-belonging/","Diversity, inclusion and belonging",{"text":1121,"config":1122},"Modern Slavery Transparency Statement",{"href":1123,"dataGaName":1124,"dataGaLocation":883},"https://handbook.gitlab.com/handbook/legal/modern-slavery-act-transparency-statement/","modern slavery transparency statement",{"items":1126},[1127,1130,1133],{"text":1128,"config":1129},"Terms",{"href":935,"dataGaName":936,"dataGaLocation":883},{"text":1131,"config":1132},"Cookies",{"dataGaName":945,"dataGaLocation":883,"id":946,"isOneTrustButton":74},{"text":1134,"config":1135},"Privacy",{"href":940,"dataGaName":941,"dataGaLocation":883},1791340123479]