# GitBook

> Publishes product documentation and help articles as a searchable website, keeps the text tied to the source code through a two-way sync with GitHub or GitLab, and answers reader questions in place through a language-model search.

- Vendor: GitBook Inc.
- Canonical URL: https://www.convios.com/en/toolbox/gitbook
- Language version: https://www.convios.com/de/werkzeugkasten/gitbook
- Area: Service & support · Cluster: knowledge base
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-09-01 · Reviewed: 2026-09-01 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Searchable documentation creates no edge, because every competitor can rent the same platform. Without it you get requests a single paragraph would have answered, and you are missing from the answers of the assistant systems that now sit between customer and vendor. The difference comes from the text itself and from the question of who owns it when the platform changes. GitBook answers the second question well, because syncing into your own repository is part of the free plan. The first question no tool answers.

## Suitability by company size

- Solo: suitable — The free plan covers this case completely, including sync with GitHub or GitLab, preview deployments and interactive API playgrounds. Anyone writing alone pays nothing and keeps the text as Markdown in their own repository.
- Mid-market: suitable — Premium costs 65 US dollars per site per month on annual billing, plus 12 US dollars per user per month. That carries a branded public documentation site with a custom domain, redirects and analytics. Moving up to the AI features costs four times as much, so before booking it, ask how many requests the assistant actually absorbs.
- Enterprise: suitable with caveats — Everything a procurement department checks sits in the Enterprise plan with no public price: SAML sign-in, a custom contract, legal and security review, plus the organization audit log that has been in beta since 14 August 2026. A selectable EU hosting location exists on no plan, including that one.

## Vendor staying power

Established: The service has been running for years and ships weekly. The contracting entity is a Delaware corporation. The French subsidiary that the vendor still names in its own security pages has been recorded as closed in the French register (Registre national des entreprises) since 3 November 2023; the vendor names neither an EU entity nor a representative under Article 27 GDPR anywhere.

- Registration of the French entity: GITBOOK, SIREN 829 909 464, registered on 1 June 2017, last registered office 3 Cours Charlemagne, 69002 Lyon (source: https://recherche-entreprises.api.gouv.fr/search?q=gitbook, as of 2026-09-01)
- Register status of the same entity: recorded as closed since 3 November 2023 (état administratif "cessé"), while the vendor's security pages still named it as a subsidiary on 1 September 2026 (source: https://recherche-entreprises.api.gouv.fr/search?q=gitbook, as of 2026-09-01)
- Contracting entity: GitBook Inc., a Delaware corporation; the terms of service name no EU contracting entity (source: https://gitbook.com/docs/policies/terms, as of 2026-09-01)
- Certification: SOC 2 Type II, audited by Prescient Assurance, report available on request through a trust portal; ISO/IEC 27001 was announced on the vendor's own blog on 29 September 2023 and since then appears only on the pricing page (source: https://gitbook.com/docs/policies/privacy-and-security/security/security-as-a-company-value, as of 2026-09-01)
- Release cadence: public changelog with weekly entries, most recently on 27 August 2026, with yearly archives going back to 2023 (source: https://gitbook.com/docs/changelog/readme, as of 2026-09-01)
- Operations: per the vendor's own status page for June to August 2026: application 99.86 percent, published content 99.98 percent, no open incidents (source: https://www.gitbookstatus.com/, as of 2026-09-01)

## Cost of leaving

Low: The text sits as Markdown in your own repository on GitHub or GitLab, and that sync is part of the free plan. The substance therefore leaves without negotiation. What stays behind is the publication: redirects, access control for non-public pages, the analytics and the accumulated record of questions and answers in AI Insights. After termination the terms of service allow 60 days for an export.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | yes, publicly downloadable as a PDF and incorporated into the terms of service — Section 8.4 of the terms of service expressly incorporates the data processing addendum, the document hangs off the privacy statement and needs neither a request nor a particular plan. The linked version carries the file name 2022-gitbook-dpa.pdf and is therefore older than the AI features the vendor runs today. | evidenced | 2026-09-01 |
| Storage location | data centres in the United States, no selectable EU hosting location on any plan — The vendor names the location clearly: customer data sits in data centres in the United States, and HTML pages and assets may be cached in other geographies by the CDN. A selectable hosting location appears in none of the four plans on the pricing page, Enterprise included. The consequences are therefore assessable, but the customer has no choice. | partially evidenced | 2026-09-01 |
| Subprocessors | public list of 19 entries, each with purpose and country, all of them the United States — The list names Google Cloud and Firebase, Cloudflare, Planetscale, Clickhouse, Turbopuffer and OpenAI among others. Complete it is not: the same vendor's security FAQ names Clearbit for sign-up risk evaluation and Vercel for hosting, and neither appears on the list. Anyone using it as the basis for the right to object under the data processing addendum is working from a chain that is too short. | partially evidenced | 2026-09-01 |
| Third-country transfer | processing in the United States, based on the standard contractual clauses under modules one, two and three — The addendum incorporates the Commission's clauses under implementing decision 2021/914, chooses Dutch law and Dutch courts, and covers Switzerland and the United Kingdom separately. Two passages are out of date: section 4.2 still lists "Privacy Shield" as a permissible transfer solution, although the Court of Justice of the European Union invalidated it on 16 July 2020, and the privacy statement invokes the Privacy Shield principles. The vendor never mentions the EU-US Data Privacy Framework. Which recipient operates on which basis is likewise stated nowhere. | partially evidenced | 2026-09-01 |
| Training on customer data | training on customer content is ruled out, but the commitment sits on a documentation page rather than in the contract — The AI policy rules out training on customer content, for the vendor's own models as well as for OpenAI, and extends that commitment to all content whether or not AI features are switched on. Under section 8.4 of the terms of service, however, only the security documentation and the data processing addendum are incorporated into the contract, and the AI policy is not. The vendor names two carve-outs itself: GitBook Agent and Channels run without zero data retention at OpenAI, and the "Open in ChatGPT / Claude" action forwards the page under the visitor's own account, where the vendor's commitments expressly do not apply. | partially evidenced | 2026-09-01 |
| Retention and deletion | no deletion deadline for customer content after termination; 60 days for the export, 90 days for the user profile on request — The heading is worth a look here. Section 3.6 of the data processing addendum is titled "Obligation to Delete and Return Personal Data", while the text below it grants only the right to delete customer data yourself during the term. Annex 1 points to exactly that section when asked for the retention period. Section 7.3 of the terms of service allows 60 days for an export after termination and promises no deletion. In the end only a peripheral item carries a number: the user profile, deleted within 90 days of a request. | partially evidenced | 2026-09-01 |
| Certifications | SOC 2 Type II documented with a named auditor; ISO/IEC 27001 appears on the pricing page and not on the compliance page — The compliance page names only the SOC 2 Type II attestation, identifies Prescient Assurance as the auditor and releases the report on request through a trust portal. The pricing page meanwhile carries the line "ISO 27001 & SOC 2 certified" across all four plans, and a blog post dated 29 September 2023 announces both certifications. The version of the standard, the scope, the certificate number and the certification body for ISO/IEC 27001 appear nowhere, and the compliance page has not picked up the point in three years. Anyone who needs the evidence should request it before signing. | partially evidenced | 2026-09-01 |
| EU AI Act, Article 50 | unclear — The European regulation on artificial intelligence appears nowhere in the terms of service, the privacy statement, the AI policy, the security pages or the pricing page, although GitBook Assistant speaks directly to visitors on published sites. These five documents were reviewed in full on 1 September 2026. Labelling under Article 50 therefore stays with the operator, who can place it on their own documentation site; the feature can be switched off per organization and per site. | partially evidenced | 2026-09-01 |
| Audit logging | organization audit log only on the Enterprise plan, in beta since 14 August 2026, with no stated retention period — The API reference is explicit: reading the events requires an active Enterprise plan, and access is limited to organization administrators and vendor staff. Recorded are the time, the action, the actor, the entry point and the affected resource, retrieved page by page at a maximum of 100 events. How long events are kept appears neither in the API reference nor in the changelog, and the feature comparison on the pricing page does not mention the point at all. Evidence obligations cannot be planned on that basis. | partially evidenced | 2026-09-01 |

## Cost

- Entry: The free plan carries one site with editor, sync to GitHub or GitLab, preview deployments and interactive API playgrounds. Premium costs 65 US dollars per site per month on annual billing, Ultimate 249 US dollars. On top of that come 12 US dollars per user per month. Enterprise is priced on request only. (as of 2026-09-01)
- Where it gets expensive: In two places. First the vendor bills per site and additionally per user, so every separately documented product triggers the site price again. Second the Assistant, AI Insights, GitBook Agent and access control for non-public pages only start in Ultimate, which is four times the Premium price. To put numbers on it: fifteen people and two public documentation sites with the Assistant come to 678 US dollars a month on annual billing, and SAML sign-in, a custom contract and the audit log are not yet included. Those sit one step higher in Enterprise, with no public price.

## Three routes compared

### The help centre inside the helpdesk

The established counterpart is the help centre that ships with the helpdesk; at Zendesk it is called Guide. Large companies stay with it because article, ticket, rule and reporting live in one permission model, and because the path from an unanswered article to a ticket works without a second login. You pay for that with an authoring environment developers avoid, and with text that sits in the helpdesk's database rather than in a repository the customer owns.

### Documentation built for language models

Mintlify starts from the same idea and aims its delivery at language models and agents from the outset. The price is cut differently: Starter costs nothing and includes a custom domain, reader authentication and an MCP server for five editor seats, while Pro sits at 450 US dollars a month for unlimited seats, as of 1 September 2026. At GitBook the same scope hangs off two plan steps and off the number of people. What you give up is breadth: fewer authoring features for staff without Git, a younger vendor and a shorter evidence trail on regulatory questions.

### Your own documentation site from building blocks

Building this yourself is unusually cheap, because the blocks are ready. Astro renders the pages, Sanity holds the text for everyone who does not use Git, Cloudflare Pages serves it, Ory protects the non-public parts, and LiteLLM as a model gateway plus Langfuse as a log belong in front of the answering feature. The build runs with Claude Code or Cursor. Assuming a day rate of 1,000 euros, a serviceable first version takes eight to twelve person-days, plus under 50 euros a month for delivery and model calls at low load. It fails in three places: at search, which is weaker than the bought one after the first month; at redirects and versioning, which nobody wants to maintain; and at upkeep, once the builder leaves the building.

Recommendation by size:

- Solo: Buy, free plan. Syncing into your own repository is already included there.
- Mid-market: Buy, Premium. Before moving up to Ultimate, measure how many requests the Assistant actually absorbs.
- Enterprise: Buy only on an Enterprise contract, and write hosting location, deletion deadline after termination and audit log retention into it.

## Context

- Implements method: [Service Blueprinting](https://www.convios.com/en/methods/service-blueprinting) — A blueprint shows where the customer gets through on their own and from which point a person takes over, and a knowledge base is precisely the step you push in front of that handover.
- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The test asks how much regulation attaches to a process, and here the answer decides the purchase: US-only hosting with no choice carries a public product documentation site and does not carry a knowledge base holding customer data.
- Implements method: ["Context: Moat or Wall?" Test](https://www.convios.com/en/methods/context-moat-or-wall-test) — The test separates what creates an edge from what merely keeps you level, and a rented documentation platform visibly belongs to the second group, while the text inside it can belong to the first.
- Alternative: [Zendesk](https://www.convios.com/en/toolbox/zendesk)
- Alternative: Circle
- Displaces: The manual as a PDF attached to an email, Documentation in a wiki nobody outside the company may see, Answers that exist only in the history of the support inbox

## Evidence

- Plan prices: free, Premium 65 US dollars per site per month, Ultimate 249 US dollars, both on annual billing, plus 12 US dollars per user per month; Enterprise on request — https://www.gitbook.com/pricing (as of 2026-09-01)
- SAML sign-in, a custom contract and legal and security review sit in the Enterprise plan alone; a selectable hosting location appears in no plan — https://www.gitbook.com/pricing (as of 2026-09-01)
- Customer data sits in data centres in the United States; pages and assets may be cached in other geographies by the CDN — https://gitbook.com/docs/policies/privacy-and-security/security/security-faq (as of 2026-09-01)
- The subprocessor list has 19 entries, all with the United States as the processing location; Clearbit and Vercel are named in the security FAQ and are missing from the list — https://gitbook.com/docs/policies/privacy-and-security/security/subprocessors (as of 2026-09-01)
- Section 8.4 of the terms of service incorporates the data processing addendum; section 7.3 allows 60 days for an export after termination and promises no deletion — https://gitbook.com/docs/policies/terms (as of 2026-09-01)
- The data processing addendum incorporates the standard contractual clauses under implementing decision 2021/914 in modules one to three, chooses Dutch law and still names Privacy Shield in section 4.2 as a permissible transfer solution — https://gitbook.com/docs/policies/privacy-and-security/statement (as of 2026-09-01)
- The AI policy rules out training on customer content, names OpenAI as the processor, and expressly carves GitBook Agent, Channels and the "Open in ChatGPT / Claude" action out of its commitments — https://gitbook.com/docs/policies/policies/gitbook-ai-policy (as of 2026-09-01)
- The compliance page lists SOC 2 Type II alone, with Prescient Assurance as the auditor and the report on request; ISO/IEC 27001 is not there — https://gitbook.com/docs/policies/privacy-and-security/security/security-as-a-company-value (as of 2026-09-01)
- A blog post dated 29 September 2023 announces SOC 2 Type II and ISO/IEC 27001 and refers to the sales team for the reports — https://www.gitbook.com/blog/gitbook-security-soc2-iso27001 (as of 2026-09-01)
- Reading organization audit events requires an active Enterprise plan, is restricted to administrators and vendor staff and returns at most 100 events per page; no retention period is stated — https://gitbook.com/docs/developers/gitbook-api/api-reference/organizations/list-organization-audit-events (as of 2026-09-01)
- The organization audit log was announced in the changelog on 14 August 2026 as a beta for Enterprise; the most recent release entry is dated 27 August 2026 — https://gitbook.com/docs/changelog/readme (as of 2026-09-01)
- The French company register lists GITBOOK, SIREN 829 909 464, registered on 1 June 2017 and closed on 3 November 2023 — https://recherche-entreprises.api.gouv.fr/search?q=gitbook (as of 2026-09-01)
- Mintlify charges nothing for Starter and 450 US dollars a month for Pro with unlimited editor seats — https://mintlify.com/pricing (as of 2026-09-01)
- The vendor's own status page reports availability of 99.86 percent for the application and 99.98 percent for published content from June to August 2026 — https://www.gitbookstatus.com/ (as of 2026-09-01)
