- Deployment
- self-hosted-weights
- Hq Country
- United States
- Hq City
- San Francisco
- Ownership
- public
- Founded
- 2014
- Training Default
- never
- Residency Options
- the customer's own network, fully isolated / offline networks with an offline licence
- Gov Access Exposure
- none-eu
- Eu Ai Act Role
- deployer
- Certs
- ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, CSA Trusted Cloud Provider
- DPA available
- yes
- Zero Retention Available
- Yes
- Self Host Option
- Yes
- Retention Default
- "Inference data, including code inputs, model prompts, and model responses, does not leave the customer network." GitLab does not train generative AI models, and its model sub-processors are contractually barred from training on input or output.
- Retention Exceptions
- With an online licence, a JSON billing record leaves the network: instance ID, a SHA-256 de-identified GlobalUserId, a call count and a timestamp — no prompts. With an offline licence the instance does not connect to GitLab's billing components at all. This row grades the fully self-hosted configuration; the GitLab.com AI Gateway path routes to Anthropic, Fireworks AI and Google Vertex and is a different product shape.
- Subprocessors
- none in the inference path when the AI Gateway and the models are self-hosted — GitLab's published list (Google LLC, AWS, Zendesk, Fireworks AI) applies to the GitLab-managed gateway
- Subprocessor Count
- 0
- Transfer Mechanism
- intra-eu
- Eu Procurement Ready
- pass
- Eu Procurement Reason
- The clearest example in this batch of a US vendor selling a genuinely sovereign configuration, and it does it by getting out of the way. Run your own AI Gateway and your own models — vLLM on your metal, or Bedrock and Azure OpenAI behind your gateway — and GitLab's documentation commits in plain words that code inputs, prompts and responses do not leave the customer network. An offline licence removes even the billing callback. Everything else is unusually well disclosed for this category: a complete sub-processor table, ISO 27001:2022 with 27017 and 27018, SOC 2 Type 2, and an explicit statement that model sub-processors are barred from training. The caveat is that all of this belongs to the self-hosted configuration and a Premium or Ultimate tier plus the Duo add-on; the default GitLab.com gateway sends prompts to Anthropic, Fireworks and Google Vertex in the US and would score like the rest of the hosted field.
- Training Claim Basis
- stated
- Training Confidence
- high
- Residency Claim Basis
- stated
- Residency Confidence
- high
- Retention Claim Basis
- stated
- Retention Confidence
- high
- Subprocessors Claim Basis
- stated
- Subprocessors Confidence
- high
- Residency Class
- customer-controlled
- Portability / Exit Path
- serves-open-models
- Subprocessor Jurisdiction
- structurally-none
- Underlying model providers
- customer-selected — vLLM, AWS Bedrock or Azure OpenAI behind a self-hosted AI Gateway