Trust
Everything your security or legal team needs to evaluate gittan, on one page.
Who runs gittan
Gittan is built and operated by Bloomer AB (org. nr 559490-9498), a Swedish company based in Gothenburg. All infrastructure is in the EU. There is no US parent company, no venture investor with board access, and no CLOUD Act exposure.
Bloomer AB is a small company. We don't hide that — you can verify it on allabolag.se. What we offer in return is full transparency, a clear exit path, and a platform built by a platform engineer with 26 years of experience in regulated environments.
Data processing
When your organization uses gittan, we process personal data (account details, commit metadata, audit logs) on your behalf. Under GDPR, your organization is the data controller and Bloomer AB is the data processor.
Our Data Processing Agreement is part of the Terms of Service, accepted at registration. It covers Art. 28 GDPR requirements: purpose limitation, sub-processor obligations, data return, and deletion. No separate negotiation needed — the DPA applies to every customer equally.
Sub-processors
We use as few sub-processors as possible. All process data within the EU.
| Provider | Purpose | Location |
|---|---|---|
| Scaleway | Compute, storage, databases, object storage | Paris & Amsterdam, EU |
| Stripe | Payment processing, invoicing | EU (Ireland) |
| Scaleway TEM | Transactional email (notifications, support replies) | Paris, EU |
We will notify you before adding a sub-processor. This list was last updated October 2026.
Security measures
Technical and organizational measures under GDPR Art. 32:
- Encryption in transit — TLS 1.3 on all connections (web, git, API, registry)
- Encryption at rest — all storage volumes and database backups are encrypted
- Authentication — OIDC only, no passwords stored. Per-session tokens with automatic expiry
- Authorization — role-based: organization members read, team members own. No cross-team access
- Audit log — every push, pipeline run, settings change, and member action is logged with actor, timestamp, and outcome
- Security scanning — automated on every push: secret detection, dependency vulnerability scanning, container image scanning
- Network isolation — services communicate over private networks. Pipeline runners are isolated per execution
- Pipeline gating — no code reaches main without passing all pipeline stages. Org-level policies cannot be bypassed by individual developers
For technical details, see the security documentation.
Incident response
If we discover a breach affecting your data, we notify your organization without undue delay — and always within a timeframe that lets you meet the 72-hour reporting obligation to your supervisory authority (GDPR Art. 33).
Notification includes: what happened, what data was affected, what we are doing about it, and a contact for follow-up questions.
Data portability and exit
Gittan uses standard git. Every repository is a regular git repo that you can clone
with git clone at any time. Your full history, branches, and tags come with it. There is no proprietary
format and no export fee.
- While active — clone your repos whenever you want. Pipeline configs are YAML in the repo or downloadable via the API
- On cancellation — your data remains accessible until the end of the billing period. After that, repos are retained for 30 days before deletion
- On request — we provide a full data export (repos, pipeline history, audit log, org settings) within 10 business days
If gittan shuts down, we commit to giving customers at least 90 days' notice and keeping read access open during that period so you can migrate.
Uptime
We target 99.9% monthly uptime for git operations and the web interface. Pipeline execution depends on runner capacity and is not covered by the uptime target.
Current status and incident history: status.gittan.eu
Change management
Gittan does not use pull requests. Instead, every push to main runs through a gated pipeline: tests, security scanning, and org-level policies must pass before the push lands. The pipeline is the control — automated, deterministic, and not bypassable by the person who pushed.
This model satisfies the change management requirements in ISO 27001, SOC 2, NIS2, and DORA. For the full breakdown — separation of duties, audit trail, compliance mapping — see the dedicated change management page.
Liability
Bloomer AB's liability is limited to the amount paid for the service in the 12 months preceding the claim, as detailed in our Terms of Service. We are not liable for indirect, incidental, or consequential damages.
Questions
Security or legal questions: security@gittan.eu
Privacy and data processing: privacy@gittan.eu
Last updated: October 2026