Install and scope the connection
Connect over OAuth or an app install and choose exactly what GitLab shares — you can revoke it on your side at any time
GitLab connects over OAuth for two-way remediation issues, cloud or self-hosted. Alongside the sync, read-only checks verify enforced two-factor authentication, project visibility and protected default branches across your group.
4 read-only checks, run on a schedule. Each failure becomes a finding linked to a control — every check is listed, none are “coming soon”.
Confirms the token can read the target group over the GitLab API.
group-connectivity
Fails if the GitLab group does not require all members to enable two-factor authentication. `require_two_factor_authentication` is only accurate when the token owner administers the group.
group-two-factor-required
Fails if the project's visibility is `public`, meaning its source is readable by anyone.
project-not-public
Fails if the project's default branch is not in the protected-branches list, or if that protected-branch entry allows force-push. Only exact-name protection rules are evaluated: a wildcard rule (for example `main*` or `*`) is not matched even though it does protect the branch.
default-branch-protected
Bring your current platform's test list — we'll map it against these checks, gap by gap
Create issues in your GitLab projects, cloud or self-hosted, and keep each one in step as its status changes, connected over OAuth.
Setup is minutes, not a migration project — and every step stays on your side
Connect over OAuth or an app install and choose exactly what GitLab shares — you can revoke it on your side at any time
The first run starts right after connecting, then repeats on a schedule. Results are timestamped, so your evidence has a history, not a snapshot.
Passing results attach as evidence to the controls they support; failures become findings you triage. When the audit comes, the proof is already connected.
Open any page for its full check register.
You create and scope every credential yourself, and you can revoke it at any time. Checks only read; results and evidence are stored in Switzerland and stay exportable.
Yes. The checks authenticate with a credential you create and scope yourself, and only ever read configuration. devguard holds no write access to GitLab and remediates nothing silently.
A failed check becomes a finding linked to the control it supports, with the evidence attached. You decide the treatment — nothing pages your engineers and nothing is auto-remediated.
Checks run from Swiss infrastructure, and results and evidence are stored in Switzerland. Everything is exportable — your evidence stays yours.
20 minutes on how you run certification today. Bring your current test or control list and we'll map it against these checks — honestly, gap by gap.