GitLab
Follow
Confidential AI for GitLab Self-Hosted
Regulated organizations face a dilemma with AI coding agents, as their proprietary source code cannot be sent to third-party AI services due to strict compliance and IP protection policies. Running AI models in-house requires significant investment in scarce hardware and specialized staff, while still falling behind cutting-edge models. This leads to teams using AI falling behind competitors. GitLab Duo Self-Hosted now offers a solution by integrating with Privatemode AI, which utilizes confidential computing hardware. This ensures that prompts and source code remain encrypted end-to-end, even during inference, as they never leave a secure, encrypted boundary. Privatemode's confidential computing leverages hardware-based trusted execution environments (TEEs) and remote attestation to cryptographically prove the integrity of the AI model's execution. This architectural approach provides a stronger guarantee than contractual agreements, as even the service operator cannot access the plaintext data. The integration allows developers to use advanced AI features like code review and test generation without compromising data security or violating regulations like GDPR, NIS2, and DORA. While this solution requires operating the AI Gateway and Privatemode proxy, it avoids the immense burden of managing GPU clusters and LLM operations. Confidential computing narrows the trust assumption to the hardware itself, offering a practical path for regulated industries to adopt modern AI coding tools safely and effectively.