GitLab Duo with Amazon Q
GitLab · Operations & Productivity
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
GitLab Duo with Amazon Q brings together GitLabs comprehensive DevSecOps platform with Amazon Qs advanced AI agents to deliver a seamless developer experience. This integration enables developers to handle complex, multi-step tasks across the entire software development lifecycle - from automatically generating merge requests based on user stories, to streamlining security and deployment workflows. By embedding Amazon Qs capabilities directly into GitLabs daily workflows, teams can ship secure software faster while maintaining all the benefits of a unified DevSecOps platform while streamlining workflows across AWS and GitLab.
GitLab will deliver an activation code after the transaction is completed. To utilize GitLab Duo with Amazon Q features and capabilities, users must download and install the GitLab product. Detailed instructions for installation of GitLab can be found at https://about.gitlab.com/install/. Instructions on how to activate the product with the activation code can be found at https://docs.gitlab.com/ee/administration/license.html#activate-gitlab-ee. Instructions on enabling GitLab Duo with Amazon Q can be found at https://docs.gitlab.com/user/duo_amazon_q/setup/.
Highlights
Highlighted by the publisher on AWS Marketplace.
Comprehensive DevSecOps platform for the entire SDLC enhanced by Amazon Q. GitLabs unified data store paired with Amazon Q to accelerate software development without complex toolchains.
Enterprise-grade security and compliance are built in. Reduce risk with a unified platform for automating secure code from commit to production.
AI agents perform tasks across your workflow, from planning to AI-driven test generation, automated merge request reviews, and Java codebase upgrades.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMP AuthorizedConfirmed95%, domain-verifiedGitLab Dedicated for Government is FedRAMP Authorized at Moderate impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-23
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

