Gitlab hero border pattern left svg Gitlab hero border pattern right svg

DM.4.01 - Encryption of Data in Transit Control Guidance

DM.4.01 - Encryption of Data in Transit

Control Statement

GitLab encrypts red, orange, and yellow data transmitted over public networks.


Encrypting data transmitted over public networks helps ensure the confidentiality and integrity of that data. Without encryption, data in transit over public networks can easily be intercepted using automated, open source tools and viewed and maliciously modified by malicious actors.


This control applies to red, orange, and yellow data in the production environment. The production environment includes all endpoints and cloud assets used in hosting and its subdomains. This may include third-party systems that support the business of



Additional control information and project tracking

Non-public information relating to this security control as well as links to the work associated with various phases of project work can be found in the Encryption of Data in Transit control issue.

Examples of evidence an auditor might request to satisfy this control:

Policy Reference

Framework Mapping