Story
Rio Tinto Group Adopts GitLab for Secure Delivery
Rio Tinto Group, a materials organization in the United Kingdom, uses GitLab Issues from GitLab to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Productivity | Handoffs in secure delivery sit in a shared queue instead of a mailbox trail |
| Risk and compliance | Fewer stalled items because developer security has a clear owner |
| Capability | New joiners can see how secure delivery actually runs |
Story
Inside Rio Tinto Group, secure delivery used to depend on whoever still had the latest file. That pattern is common in materials groups working out of the United Kingdom. Developers and AppSec needed a system that would still make sense after the original project team moved on.
Rio Tinto Group uses GitLab Issues from GitLab as the working layer for developer security. GitLab is a DevSecOps platform that combines source control, CI/CD, security scanning, and planning in one application. The practical change is simple: secure delivery has a home, and reviews happen there instead of in a forwarded thread.
Nothing in this writeup invents a savings number. What Rio Tinto Group gets from GitLab is a durable place to run secure delivery and a way for developers and AppSec to see the same developer security at the same time.