Story
How Morningstar Runs Secure Delivery on GitLab Duo
Morningstar, a financials organization in the United States, uses GitLab Duo from GitLab to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Named workflow replaces ad hoc routing for developer security |
| Risk and compliance | Developers and AppSec work from the same GitLab Duo record for developer security |
| Capability | Secure delivery stays visible to adjacent teams through GitLab Duo |
Story
Morningstar is based in the United States and runs financials operations at a scale where developer security cannot live in side channels. Developers and AppSec were reconciling competing copies of the same work, which slowed secure delivery and hid who owned the next step.
The company runs secure delivery on GitLab, with GitLab Duo as the product developers and AppSec actually open. GitLab is a DevSecOps platform that combines source control, CI/CD, security scanning, and planning in one application. For Morningstar, that means developers and AppSec can open one workflow, see developer security, and let neighboring teams join without inventing a parallel stack.
Public materials confirm the companies and products. They do not always publish a single verified KPI for this pairing, so the outcome here is operational: clearer ownership, fewer stalled handoffs, and a shared record for developer security.