← Trust Directory

OpenAI

openai.com · 1 assessment

OpenAI - organisation
Approve
No blocking issues found in the public evidence
Assessed Aug 28, 2026 · public evidence coverage 53% · evidence confidence medium high · methodology 0.6.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2
Claimed & corroborated

SOC 2 Type 2 for the API Platform and ChatGPT business services; reports via the trust portal.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) · checked Aug 28, 2026

ISO/IEC 27001
Claimed & corroborated

ISO/IEC 27001:2022 for systems supporting the API, ChatGPT Enterprise and Edu.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (OpenAI trust portal) · checked Aug 24, 2026

Valid until Aug 7, 2028

ISO/IEC 27701
Claimed & corroborated

ISO/IEC 27701:2019 is corroborated as an EXTENSION WITHIN OpenAI's ISO/IEC 27001:2022 certificate 1404936-1 (Schellman, ANAB), not as a standalone 27701 certificate. The certified scope extends to the PIMS requirements and additional control set of 27701:2019 in the role of a PII processor, covering the API, ChatGPT Enterprise and ChatGPT Edu services; SoA v2 dated 29 May 2025.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IAF CertSearch · checked Aug 24, 2026

ISO/IEC 42001
Claimed & corroborated

AI management system covering consumer and business AI products and models.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (OpenAI trust portal) · checked Aug 24, 2026

Valid until Dec 10, 2028

PCI DSS
Claimed & corroborated

Delegated payment components of ChatGPT.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · PCI DSS v4.0.1 Attestations of Compliance (Service Providers and Merchants), OpenAI trust portal download supplied by Robbo 2026-08-28 · checked Aug 28, 2026

CSA STAR Level 1
Claimed & corroborated

Level 1 self-assessment, not third-party assessed.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 28, 2026

SOC 2 Type 2
Claimed & corroborated

SOC 2 Type 2 by Schellman & Company, period 1 Jan - 30 Jun 2025, system: API and ChatGPT Business Product Services; trust services criteria security, availability, confidentiality AND privacy (four - broader than Perplexity's three, which omit privacy). SCOPE IS THE BUSINESS OFFERINGS ONLY, the same boundary as OpenAI's ISO/IEC 27001 certificate; consumer ChatGPT is outside it. NOTE FOR BUYERS: this is the SAME ENGAGEMENT as the already-corroborated SOC 3, which is its general-use summary - they are one attestation reported two ways, not two independent ones. The period ended 30 Jun 2025, so the report is over a year old; ask for the current period or a bridge letter. Vault: Gated/OpenAI/2025-06_openai-soc2-type2-schellman.pdf.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) · checked Aug 24, 2026

CSA STAR Level 2
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 28, 2026

SOC 3
Claimed & corroborated

SOC 3 Type 2, period 1 Jan 2025 - 30 Jun 2025, unqualified; trust services criteria security, availability, confidentiality and privacy. System: API and ChatGPT Business Product Services - BUSINESS OFFERINGS ONLY, the same boundary as OpenAI's ISO/IEC 27001 certificate; consumer ChatGPT is outside it. TWO LIMITATIONS A BUYER SHOULD WEIGH: the period ended 30 June 2025, so the report is over a year old and procurement would normally ask for the current period or a bridge letter; and a SOC 3 does NOT substitute for the SOC 2 Type 2 that OpenAI separately claims - it derives from that engagement but is a different report, so the SOC 2 claim stays uncorroborated. Vault: Gated/OpenAI/2025_openai-soc-3-report.pdf.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · SOC 3 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) · checked Aug 24, 2026

FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 28, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

Subprocessors: Cloudflare

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.