Creating a Security page on the site to explain your infosec policies would go a long way. I like that we're able to view previous disclosures [1] and active security issues [2], but I had to dig a bit to find them. Surface those.
[1] https://about.gitlab.com/vulnerability-acknowledgements/
[2] https://gitlab.com/gitlab-org/gitlab-ce/issues?label_name%5B...