My day job has me interfacing with GitHub quite a lot. Anyone in a similar position knows that, over the last year or so, GitHub has frequently found itself on the struggle bus.
All the woes got me thinking a little bit about GitLab (NASDAQ: GTLB) and what potential it has in the world of enterprise software. It’s a company with a great story to tell, and lots to break down.
The Invisible Domain of Software Development
Developing and selling software is a lot more involved than simply typing syntax. That’s only one part of the puzzle and GitLab covers half the pieces.
You’re going to want to plan things out. GitLab isn’t really playing in that space so we can safely disregard it.
Once you’ve planned things out you’ll write the code. With potentially hundreds of software engineers working at any one time on the codebase there needs to be a system for organizing all that code and making sure no one steps on another’s toes. That system is Git.
Engineers can write their code, open a “pull request” and then merge that code into the main branch of the software they’re developing. GitHub, GitLab and others like Atlassian’s Bitbucket run services that help make working with Git easier overall.
After that comes a whole bunch of “invisible” stuff. There’s the CI/CD pipelines (continuous integration / continuous delivery). These are the pipelines that automatically run tests, deploy software, configure services, and keep things running. There’s security to handle too, making sure the code is clean and packages are always kept up to date. If all those are handled well you’re going to need to prove it out which is where compliance logs come in.
Every one of those steps above, GitLab handles. GitHub handles them too (with Actions, Advanced Security). There are also a number of third parties that handle these steps individually too.
GitLab’s Edge - An Upper-Market Monopoly
While there are many competitors in the space, there is a distinct advantage that GitLab carries: its ability to work with customers who are under strict national security controls.
Could GitHub work with the DoD? Maybe. But the Department of Defense, many of the contractors that work with the DoD, and lots of other regulated entities side with GitLab more than GitHub.
GitHub offers Enterprise Server, a self-hosted instance but it is packaged as a closed-source, black-box virtual appliance. GitLab is a Kubernetes-native open-core piece of software. Under initiatives like Platform One and Iron Bank, the military can harden GitLab. They can’t do so with GitHub.
GitLab also comes as one package. You’re not having to piece things together, add in plugins, integrate vendors. If you’re in a mission critical area and need one vendor to handle everything, GitLab is a solid choice.
If you need open-source and the ability to verify / validate every touchpoint your code goes through, GitLab has you covered. If you’re in Europe and subject to the DORA framework (like the banks are) you might already struggle using GitHub due to vendor concentration risks. Using GitLab means you’re still able to be on Azure.
The US CLOUD Act also presents some challenges as well for GitHub when it comes to large international corporations who want to control their data. If a US company has “possession, custody, or control” of the data or encryption keys, they have to hand it over. GitLab’s self-managed instance is essentially a sovereign fortress.
The Switching Costs
One domain where GitLab will struggle is on getting existing enterprises to switch. To switch your git repos takes time, to change your CI/CD pipelines is risky.
No one really wants to take on these kinds of risks and tell the CEO, “hey, we’re slowing down development on new features for a bit.” So how does GitLab compete?
Well, first has to be the consolidating sale. GitLab might not have to convince a CTO to go beg for the change, they might be able to convince the CEO or CFO themselves with a look at potential savings.
GitHub, Circle, Snyk, some other tool to monitor compliance, they can easily run up to $120-150 per engineer. GitLab’s top offering is $99 per engineer. Their sales team could make the pitch of “one vendor, not several for one lower price.”
A team of 1000 saving $600k/year and only having to deal with a single vendor can be an easy sell in a time of cost cutting, a finding backed up by Forrester’s Total Economic Impact Study showing a 483% 3-year ROI for Ultimate consolidation.
Another way they potentially make those switching costs come a little easier is by offering the tooling in stages. A company can integrate GitLab’s CI/CD tooling into their existing GitHub workflows with ease and then change to GitLab’s code repositories over time.
The SMB Dilemma
Turning now to the business side of things a little more, I’d like to start out with a concern. A little while back, GitLab made the decision to step away from the SMB market and the hobbyists. Those markets are effectively free for GitHub to land.
Wall Street, of course, rewarded the decision. By focusing on Fortune 2000 and larger foreign entities, GitLab is putting itself in a position to benefit from a massive operational margin tailwind.
The costs of servicing SMB is higher, the costs of hobbyists is high too. Thousands of small companies at $9/month can be replaced by one or two large entities paying $99/mo for their engineers.
The dilemma I think GitLab will face though is losing out on that next generation of seed startups (the next Stripe, the next OpenAI).
Startups will not pay the $29 GitLab price point out the gate and, as we discussed above, will have a hard time switching barring a lot of push from people within the org. A lot of these companies may just stick with the status quo as long as it’s not actively harming things.
So the tailwind that GitLab receives now may well turn into a structural challenge three to five years from now. GitHub may solve its tech issues, it may broaden its offerings in some way to capture other markets, all while GitLab is sitting back and focusing on the Fortune 2000.
In fairness, if you’re going to focus somewhere, the Fortune 2000 is pretty good.
Back To Positive: The AI Paradox
AI is supposed to make us all efficient and it is succeeding in the software engineering world. It used to be that writing code was the bottleneck to progress but those days are now behind us.
Bottlenecks now exist downstream from the code writing. There’s a blockage at the review phase, the CI/CD phases, and on infosec teams keeping on top of all that’s getting delivered.
AI has allowed engineers to create more, much more. It’s partly the reason why GitHub is on the struggle bus as much as it is GitHub Incident History. GitLab is building for that future. Their goal is to build the platform to handle 100x the demand it sees today.
Growth in the shipping of code means that companies will require bigger CI/CD workflows. They’ll require better infosec tooling too, tied right into their codebases and GitLab can handle that.
The company is also down the path of building tooling for agentic development. Agent based code review guidance already exists. In times of old (two years ago, ha) engineers would have to comb through lines of code to make sure what was being shipped was coded effectively.
Now? Well you can have agents do a significant first pass which should save time and, in a virtuous cycle, give engineers time back to ship even more, backed by a Forrester Study showing a 400% 3-year ROI on the Duo Agent Platform.
The expansion and building out of this agentic platform, Duo Agent, means that GitLab has the potential to rake in incremental income from customers by charging usage credits for these AI workloads.
The Money Troubles
Seems a bit weird to write “money troubles” about a company with $1.36B in cash on the balance sheet, right? Well, it is. I’m actually talking about stock based comp at the company.
Stock-based compensation eats up effectively the entirety of free cash-flows. According to GitLab’s SEC Form 10-Q, Free Cash Flow comes in at $263.4M, a fantastic 26.2% margin over the last twelve months. Stock based compensation of $209.2M means that actual owner FCF ends up settling at $54.2M. A true owner FCF margin of 5.4%.
The good news is that things are looking a little better in Q1 of 2027 than they were in Q1 of 2026 so the ship may very well be turning, although it is a slight turn.
The CEO, Sid Sijbrandij, is fond of remote work (hey, me too), and also fond of keeping engineers around which requires, at least for some of the higher levels of talent, a nice pay package.
Getting SBC under control was actually the thing that drew me towards the company. I was using our cannibal and reinvestor screeners and thought to myself, “are there opportunities for companies to move into these buckets?” GTLB came up as a top contender.
Others? ADSK which is already undergoing activist involvement, and DocuSign. Two other cash cows that could do a better job of capital allocation and it would seem GitLab is no different.
Could the company succeed on its current path? Sure. Is there a chance for fantastic returns with corrections? Absolutely.
Because GitLab already generates ~26% standard cash margins, every 500 bps reduction in SBC drops straight to the bottom line. Taking SBC from 20% down to 10% of revenue would almost triple owner FCF and compress the EV / Owner FCF multiple down from 86x to 32x.
In the spirit of our cannibal portfolio, a GTLB at 10% SBC when combined with GitLab’s existing cash hoard could very quickly transition from a share diluter to a compounder. In fact, they could run that playbook right away with the cash on hand, unless they have better things to spend that cash on.
The M&A Angle
At ~5.9x enterprise value to sales, 87% gross margins, and holding $1.36B in cash, GitLab is one of the premier strategic takeover targets in the software space. Rumors have circulated of interest from many parties including Alphabet (which owns a chunk already), Datadog, and even some massive private equity firms.
So why hasn’t an acquisition happened yet?
There are a few roadblocks in the way...
The Founder Vote
Founder and CEO Sid Sijbrandij controls ~45% of the voting power via Class B shares. A hostile takeover cannot happen. He has to approve and personally sign off on the price and terms or the deal has to be so good to somehow convince every one of those other shares to vote in favor.
Antitrust
Regulators blocked Adobe’s acquisition of Figma for $20B. That rightfully makes other big tech question if they can get away with an acquisition.
Google is a solid suitor for GitLab. They could integrate it into their Google Cloud Platform. But is it worth running the risk of an 18-to-24 month regulatory review? Maybe not.
PE Dilemma
Private Equity buying GitLab makes sense. It’s a company that, at the surface level, is not making the best use of its resources. In the eyes of private equity the best use of all that cash is in returns to their shareholders.
But if PE was to buy GitLab and immediately slash the SBC load the best engineers will head for the door right away. With an open-source core, some of those engineers might even build competitors by forking a codebase they’re already familiar with.
There’s more to this article for our premium subscribers. You’ll get an in depth look at the valuation including our bear, base, and bull cases along with the actions we’re taking in the TechBreakdowns portfolio.






