MASHINIi

GitLab Inc..

GTLB.US | Computer programming activities

GitLab Inc. is a software development company that provides a web-based DevOps platform. The platform offers a single application for all stages of the DevOps lifecycle, from planning and source code management to CI/CD, monitoring, and security. GitLab's platform enables teams to collaborate on cod...Show More

Ethical Profile

Mixed.

GitLab Inc. holds a 'Mixed' ethical rating. The company has faced significant security challenges, including an actively exploited critical vulnerability (CVE-2023-7028, CVSS 10) allegedly enabling account takeovers, and a data breach at Europcar. A legal complaint also alleges federal securities law violations over misleading revenue projections. Employee relations show a 202:1 CEO to median pay ratio; some Glassdoor reviews cite micro-management. GitLab purchased carbon removal credits and conducted a GHG inventory, yet lacks specific net-zero targets. Its software is also used under a DoD contract, raising dual-use concerns.

Value Scores

Better Health for All0
-100100
Fair Money & Economic Opportunity0
-100100
Fair Pay & Worker Respect30
-100100
Fair Trade & Ethical Sourcing0
-100100
Honest & Fair Business40
-100100
Kind to Animals0
-100100
No War, No Weapons-50
-100100
Planet-Friendly Business-50
-100100
Respect for Cultures & Communities0
-100100
Safe & Smart Tech0
-100100
Zero Waste & Sustainable Products0
-100100

Better Health for All

0

GitLab Inc. provides a DevOps platform for software development, and its core products and services do not have a direct positive or negative impact on health outcomes. The provided article focuses on software development efficiency metrics such as time savings, cycle time reduction, and faster vulnerability detection. There is no evidence of revenue from products with negative health outcomes, nor are there direct safety implications for physical or mental health from its software. The company does not offer health-related products or services, engage in health equity programs, support healthcare workforce development, or conduct health education or research. While the platform contributes to a 17% boost in developer happiness scores, this is an indirect outcome of improved efficiency for its users rather than a direct mental health initiative or program.

1
The company's operations do not generate significant health externalities, nor does it collect or manage health-related data.

Fair Money & Economic Opportunity

0

GitLab Inc. is a software development company that provides a DevOps platform, not a financial institution.

1
The company generates revenue through subscriptions to its platform.
2
As such, GitLab does not offer lending, deposit, or insurance services to consumers, nor does it manage customer financial data or provide consumer credit products.
3
Therefore, all KPIs related to financial products, services, pricing, fees, debt, and financial inclusion initiatives are not applicable to GitLab's core business model. The rubric assigns a score of 0 for KPIs that do not apply to companies outside the financial services sector or those that do not offer consumer credit products.

Fair Pay & Worker Respect

30

GitLab's CEO to median employee pay ratio was 202:1 in 2025.

1
The company reported a pay ratio of 1.0032 for men to women in FY23, which translates to a women-to-men pay equity ratio of approximately 0.9968.
2
The employee engagement score was 81% in FY23.
3
The global voluntary turnover rate was 16% in FY23.
4
100% of full-time employees had access to benefits in both FY22 and FY23, which includes health insurance.
5

Fair Trade & Ethical Sourcing

0

GitLab Inc. is a software development company, and its business model does not involve the procurement or trade of physical commodities. Consequently, KPIs related to physical supply chains, such as fair trade certifications, supplier audits for welfare, exposure to upstream labor practices, supply chain traceability, remediation processes for sourcing violations, high-risk material spend, and supplier diversity spend, are not applicable to its operations. No evidence was found in the provided articles to suggest any activity or data relevant to these metrics within the context of a physical supply chain.

1

Honest & Fair Business

40

GitLab has a formal whistleblower protection policy that includes multiple reporting methods such as supervisors, the Chief Legal Officer, Audit Committee, Legal Team, Corporate Secretary, and 24/7 anonymous hotlines (EthicsPoint and Lighthouse Services) and an online portal.

1
The policy allows for anonymous reporting and includes retaliation prevention.
2
Country-specific policies are also mentioned, applying where they offer greater protections, and toll-free numbers are provided for various regions.
3
GitLab also has a comprehensive anti-corruption policy that prohibits bribery, kickbacks, and improper payments, emphasizing compliance with the Foreign Corrupt Practices Act (FCPA).
4
It requires prior written approval from the Chief Legal Officer for facilitating payments, political, and charitable contributions, and mandates due diligence for third-party relationships.
5
Violations can lead to disciplinary action, including termination.
6

Kind to Animals

0

GitLab Inc. is a software development company providing a web-based DevOps platform. Its core business model does not involve physical products, animal-derived ingredients, animal testing, animal agriculture, or direct impact on wildlife habitats. Therefore, all KPIs related to 'Kind to Animals' are not applicable to the company's operations. While one article mentions GitLab's platform being used for wildlife camera trap projects,

1
this does not constitute evidence of GitLab's own conservation initiatives or measurable biodiversity impact.

No War, No Weapons

-50

GitLab disclosed apparent violations to BIS and OFAC in September 2019 for inadvertently exporting software to entities in embargoed countries and on denied parties lists.

1
This resulted in a Warning Letter from BIS and a Cautionary Letter from OFAC in early 2020.
2
The company's policy prohibits users from exporting its software for end use involving sensitive nuclear, rocket systems, unmanned aerial vehicles, missiles, chemical, or biological weapons.
3
However, there is no evidence of a broader ban on all conventional arms or small arms. While the company states users may not export for end use involving certain sensitive weapons, there is no independent audit or verification of zero exposure to controversial weapons.
4

Planet-Friendly Business

-50

GitLab reported total Scope 1, 2, and 3 greenhouse gas emissions of 26,293 metric tons of CO2e for FY24.

1
The company is working to establish emission targets for FY25, but no SBTi-validated targets are currently in place.
2
In FY24, GitLab conducted its first climate risk assessment and scenario analysis in alignment with the TCFD framework.
3
This analysis covered 10 remote team member hotspots, considering physical hazards across multiple scenarios (SSP 5-8.5 and 2-4.5).
4
GitLab purchased and retired 8,580 tonnes of carbon removal credits for a reforestation program in FY24.
5
The company allocated 0.5% of its annual revenue to environmental sustainability projects in 2023.
6
GitLab assessed the climate maturity of its top 5 suppliers by spend and engaged its top 20 suppliers by spend who are not disclosing emissions data, asking them to measure and share data publicly.
7
90% of AWS global data centers' energy, which GitLab utilizes, was from renewables in 2023.
8

Respect for Cultures & Communities

0

No specific, quantitative evidence was found in the provided articles to assess GitLab against any of the KPIs for the 'Respect for Cultures & Communities' value. The articles primarily focus on internal workforce demographics, diversity, inclusion, and belonging (DIB) initiatives, and general governance, without providing data on community engagement, formal partnerships with local or indigenous groups, cultural impact assessments, local economic contributions, or specific cultural preservation efforts.

1

Safe & Smart Tech

0

GitLab has established AI Ethics Principles for Product Development and an AI Continuity Plan, along with documentation on AI features and model vendors.

1
The company holds SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019 certifications, and is a CSA Trusted Cloud Provider.
2
In 2024, GitLab's bug bounty program awarded over US$1 million in bounties, receiving 1,440 reports from 457 researchers.
3
The company takes a transparency- and privacy-first approach, guided by its AI Ethics Principles.
4
GitLab offers various security testing types, including SAST and DAST.
5
Documentation on AI model vendors' retention periods is available.
6
GitLab is compliant with GDPR, and CISA has mandated remediation for Federal Civilian Executive Branch agencies regarding a critical vulnerability.
7
A critical security vulnerability (CVE-2023-7028) in GitLab, rated CVSS 10, is actively exploited, allowing attackers to reset passwords and take over accounts.
8
Multi-factor authentication (MFA) is highlighted as a crucial countermeasure against password resets.
9
GitLab provides documentation on AI features, intended purposes, models used, data usage, and vendor retention periods.
10
The company has a Privacy Statement regarding user data control.
11

Zero Waste & Sustainable Products

0

The provided articles do not contain specific quantitative data or concrete facts related to any of the KPIs under the 'Zero Waste & Sustainable Products' value.

1
Information regarding waste diversion rates, product recyclability, packaging sustainability, recycled content, single-use plastic reduction, take-back programs, circular design principles, waste reduction initiatives, hazardous waste management, product durability, repairability, waste audit frequency, zero waste certification, waste disposal violations, material efficiency, packaging-to-product ratio, waste reduction targets, supplier waste requirements, or customer waste education is not available in the provided evidence.
2

Own GitLab Inc.?

Upload your portfolio and see how all your holdings score across 11 ethical dimensions.

Audit My Portfolio

AI-generated analysis based on publicly available data. Not financial advice. Ratings are expressions of opinion derived from automated models and may contain inaccuracies. See our Risk Disclosure for full details.