GitLab

Secure development and change evidence
Connect
Connect
More Popular integrations
DATEV
Accounting and payroll software
DocuSign
Electronic signatures
Salesforce
CRM platform

Teddy connects to GitLab with a scoped service account and collects evidence from your development process.

What Teddy collects

  • Branch protection and merge request approvals
  • Security scan results and dependency updates
  • Access rights to repositories

Frameworks and controls

  • ISO 27001:2022: A.8.25 Secure development life cycle, A.8.28 Secure coding, A.8.32 Change management, A.8.8 Management of technical vulnerabilities
  • SOC 2: CC8.1 change management, CC7.1 vulnerability detection
  • NIS2: Article 21(2)(e) security in development and vulnerability handling
  • Cyber Resilience Act: vulnerability handling requirements in Annex I

How it works

  1. You create a scoped token for the groups and projects you choose.
  2. Teddy checks protected branches, approvals, scan results and access on a schedule.
  3. Projects without protection or with open critical findings become tasks.

Access

Read-only, with optional labelled comments on merge requests. Every write is audited.

Does Teddy work with self-managed GitLab?

Talk to our team about your setup. The connection works the same way for every project you grant access to.