story
Just ask yourself and imagine this: You have a new start up company based on very valuable closed source but you entirely do not want to host my own gitlab etc. server. Which service would you use? I'm guessing it is bitbucket or github because they are offering "premium" private repos and have a good reputation (at least I do not know that a private repo there was once disclosed).
We try to achieve a good reputation by taking security seriously every day and being responsive to disclosures.
[1] https://about.gitlab.com/vulnerability-acknowledgements/
[2] https://gitlab.com/gitlab-org/gitlab-ce/issues?label_name%5B...
Anyway, I've added most information to https://about.gitlab.com/disclosure/ with https://gitlab.com/gitlab-com/www-gitlab-com/commit/eab7e345...
That page is linked from https://about.gitlab.com/contact/