OpenAI

openai.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
63 / 100C
Procurement decision
Approve
Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

OpenAI states it does not train its models on business/organisation data by default.

Evidence
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
train our models on your organization’s data by default.
How long do they keep your data?Clear

Workspace admins control retention for ChatGPT Enterprise/Edu/Healthcare; deleted conversations leave OpenAI systems within 30 days unless legally required.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days,
Vendor publishedOpenAI Data Processing Addendum | OpenAIretrieved Aug 28, 2026
return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws,
!Who else can access your data?Ask the vendor

OpenAI publishes a dated sub-processor list with entity, product, processing location and purpose.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
Where is your data processed?Clear

Data residency is available for ChatGPT and the API among enterprise compliance features.

Evidence
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
data residency for ChatGPT ⁠ (opens in a new window) and API
What happens in a security incident?Clear

The security team runs a 24/7/365 on-call rotation paged for potential incidents, alongside a bug bounty programme for responsible disclosure.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident. We offer a Bug Bounty Program⁠

Key findingsclick a row for the evidence

Certification stack now spans security, privacy and AI managementStrong

SOC 2 Type 2 (API), ISO 27001 and 27701, and an ISO/IEC 42001 AI management system covering consumer and business AI products.

42001 over the AI products directly is still rare and answers the AI-governance question at certification grade.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
API Platform has been audited and certified for SOC 2 Type 2 compliance.
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications for the information security and privacy management systems supporting the OpenAI API, ChatGPT Enterprise, and ChatGPT Edu services.
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models
!Data commitments hinge on defaults and plan tierGap

No-training applies to business data by default; retention is admin-controlled on enterprise plans. Consumer plans differ.

Which surface employees actually use determines the live posture.

Question for vendor: Confirm plan tier in use and that training-off and retention controls apply to it.

Evidence
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
train our models on your organization’s data by default.
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days,
!CSA STAR is Level 1 (self-assessment)Gap

The STAR registry evaluation cited is Level 1 transparency self-assessment, not the third-party-assessed Level 2.

Level 1 is disclosure, not independent assurance; the SOC 2/ISO set carries the independent weight.

Evidence
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing.
Moderation sharing is disclosed with boundsStrong

Flag-triggered moderation sharing with retention limited to the review period is disclosed on the sub-processor register itself.

The one data flow buyers most often discover late is documented up front.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
?Technical dependency observed: OpenAIObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on OpenAI as a model provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — OpenAI appears to be involved as a model provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score60
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedUsage policies | OpenAIretrieved Aug 28, 2026
—including these Usage Policies—set a reasonable bar for acceptable use.
AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Our commitments provide you with ownership and control over your business data (inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers and our API Platform)
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
We protect your data with thorough testing and monitoring validated by independent auditors.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,
Customer data15% of the score77
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
train our models on your organization’s data by default.
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days,
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Your content is encrypted at rest and in transit between you and OpenAI, and between OpenAI and its service providers.
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
data residency for ChatGPT ⁠ (opens in a new window) and API
Vendor publishedOpenAI Data Processing Addendum | OpenAIretrieved Aug 28, 2026
return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws,

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
OpenAI engages the following entities to provide processing activities for Customer Data (as defined in the OpenAI Data Processing Agreement).
Vendor publishedOpenAI Sub-processor list | OpenAIretrieved Aug 28, 2026
Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review,

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident. We offer a Bug Bounty Program⁠

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score100
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedEnterprise privacy at OpenAI | OpenAIretrieved Aug 28, 2026
API Platform has been audited and certified for SOC 2 Type 2 compliance.
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications for the information security and privacy management systems supporting the OpenAI API, ChatGPT Enterprise, and ChatGPT Edu services.
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models
Vendor publishedSecurity and privacy at OpenAI | OpenAIretrieved Aug 28, 2026
OpenAI maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 1retrieved Aug 28, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 42001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27701retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedOpenAI Data Processing Addendum | OpenAIretrieved Aug 28, 2026
return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws,
Vendor publishedUsage policies | OpenAIretrieved Aug 28, 2026
—including these Usage Policies—set a reasonable bar for acceptable use.
Vendor publishedUsage policies | OpenAIretrieved Aug 28, 2026
automation of high-stakes decisions in sensitive areas without human review

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Have Customer data treatment disclosures independently corroboratedData 7792
+3Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 85100
+3Publish Change management evidenceAI System 2747
+3Complete the Governance & accountability disclosureOrganisation 6080
+2Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 63 → up to 81 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESSUBPROCESSORSOpenAIOpenAIChatGPT EnterpriseChatGPT EnterpriseOpenAI API PlatformOpenAI API PlatformCloudflareCloudflare
View as list
OpenAI API Platform Uses Infrastructure Cloudflare

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 10 — registry checks and verification ladders, click to view
SOC 2Claimed & corroborated

SOC 2 Type 2 for the API Platform and ChatGPT business services; reports via the trust portal.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal), Aug 28, 2026: Verified on the registry

ISO/IEC 27001Claimed & corroborated

ISO/IEC 27001:2022 for systems supporting the API, ChatGPT Enterprise and Edu.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Aug 7, 2028

Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (OpenAI trust portal), Aug 24, 2026: Verified on the registry

ISO/IEC 27701Claimed & corroborated

ISO/IEC 27701:2019 is corroborated as an EXTENSION WITHIN OpenAI's ISO/IEC 27001:2022 certificate 1404936-1 (Schellman, ANAB), not as a standalone 27701 certificate. The certified scope extends to the PIMS requirements and additional control set of 27701:2019 in the role of a PII processor, covering the API, ChatGPT Enterprise and ChatGPT Edu services; SoA v2 dated 29 May 2025.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry

ISO/IEC 42001Claimed & corroborated

AI management system covering consumer and business AI products and models.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Dec 10, 2028

Checked against ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (OpenAI trust portal), Aug 24, 2026: Verified on the registry

PCI DSSClaimed & corroborated

Delegated payment components of ChatGPT.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against PCI DSS v4.0.1 Attestations of Compliance (Service Providers and Merchants), OpenAI trust portal download supplied by Robbo 2026-08-28, Aug 28, 2026: Verified on the registry

CSA STAR Level 1Claimed & corroborated

Level 1 self-assessment, not third-party assessed.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

SOC 2 Type 2Claimed & corroborated

SOC 2 Type 2 by Schellman & Company, period 1 Jan - 30 Jun 2025, system: API and ChatGPT Business Product Services; trust services criteria security, availability, confidentiality AND privacy (four - broader than Perplexity's three, which omit privacy). SCOPE IS THE BUSINESS OFFERINGS ONLY, the same boundary as OpenAI's ISO/IEC 27001 certificate; consumer ChatGPT is outside it. NOTE FOR BUYERS: this is the SAME ENGAGEMENT as the already-corroborated SOC 3, which is its general-use summary - they are one attestation reported two ways, not two independent ones. The period ended 30 Jun 2025, so the report is over a year old; ask for the current period or a bridge letter. Vault: Gated/OpenAI/2025-06_openai-soc2-type2-schellman.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal), Aug 24, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

SOC 3Claimed & corroborated

SOC 3 Type 2, period 1 Jan 2025 - 30 Jun 2025, unqualified; trust services criteria security, availability, confidentiality and privacy. System: API and ChatGPT Business Product Services - BUSINESS OFFERINGS ONLY, the same boundary as OpenAI's ISO/IEC 27001 certificate; consumer ChatGPT is outside it. TWO LIMITATIONS A BUYER SHOULD WEIGH: the period ended 30 June 2025, so the report is over a year old and procurement would normally ask for the current period or a bridge letter; and a SOC 3 does NOT substitute for the SOC 2 Type 2 that OpenAI separately claims - it derives from that engagement but is a different report, so the SOC 2 claim stays uncorroborated. Vault: Gated/OpenAI/2025_openai-soc-3-report.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 3 Type 2 report held in the TrustyCyber vault (OpenAI trust portal), Aug 24, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 22 — click to view
OpenAI | Research & Deployment
AI Documentation · Vendor · retrieved Aug 28, 2026
Enterprise privacy at OpenAI | OpenAI
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
OpenAI Data Processing Addendum | OpenAI
DPA · Vendor · retrieved Aug 28, 2026
OpenAI Sub-processor list | OpenAI
Subprocessor List · Vendor · retrieved Aug 28, 2026
Privacy policy | OpenAI
Privacy Notice · Vendor · retrieved Aug 28, 2026
Trust and transparency | OpenAI
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Terms of Use | OpenAI
Terms · Vendor · retrieved Aug 28, 2026
Release Notes | OpenAI | OpenAI
Changelog Or Release Notes · Vendor · retrieved Aug 28, 2026
The five AI value models driving business reinvention | OpenAI
AI Documentation · Vendor · retrieved Aug 28, 2026
Security and privacy at OpenAI | OpenAI
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Privacy policy | OpenAI
Privacy Notice · Vendor · retrieved Aug 28, 2026
Usage policies | OpenAI
Terms · Vendor · retrieved Aug 28, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 42001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 27701
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
SOC 3 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) record — SOC 3
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) record — SOC 2 Type 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (OpenAI trust portal) record — SOC 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
CSA STAR Registry record — CSA STAR Level 1
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses OpenAI at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.