ChatGPT Enterprise

openai.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
59 / 100C
Procurement decision
Approve with conditions
2 conditions outstanding
  • No clear commitment that your data will not train their models
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

OpenAI's consumer Privacy Policy states that content provided by individual users may be used to improve its services, including to train the models that power ChatGPT, subject to an opt-out. This applies to OpenAI's services for individuals (ChatGPT Free/Plus/Pro and similar), not to business offerings such as ChatGPT Enterprise.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
!How long do they keep your data?Ask the vendor

For ChatGPT Enterprise (and Edu and for Healthcare), workspace administrators control how long data is retained, and deleted conversations are removed from OpenAI's systems within 30 days unless legal retention obligations apply.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”
!Who else can access your data?Ask the vendor

OpenAI's Sub-processor list (updated 9 July 2026) names Microsoft Corporation as a cloud infrastructure sub-processor for the API, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Business, with processing locations across 23 countries including Australia, Ireland, the United Kingdom, Japan, Singapore and the United States.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
!Where is your data processed?Ask the vendor

The DPA instructs OpenAI Ireland Limited to process EEA and Swiss data and discloses that such data may be transferred to other OpenAI affiliates or third parties outside the EEA/Switzerland to provide the Services, relying on Standard Contractual Clauses or an EU adequacy decision. UK data is handled under the SCCs with the UK Addendum.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
!What happens in a security incident?Ask the vendor

OpenAI's security team operates a 24/7/365 on-call rotation that is paged for any potential security incident.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”

Email to send the vendor12 items to confirm in writing

Subject: Supplier assessment: written confirmation requested for ChatGPT Enterprise
Hello OpenAI team,

We are assessing ChatGPT Enterprise (OpenAI) as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
2. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
3. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
4. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
5. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
6. Can workspace administrators disable or centrally control the opt-in feedback/data-sharing mechanisms for all users in a ChatGPT Enterprise workspace?
7. Please provide the ISO/IEC 27001 and 42001 certificates (issuer, certificate number, validity, scope statement), the 2026 SOC 2 Type 2 report with its system description, and the FedRAMP 20x authorisation status as they apply to ChatGPT Enterprise.
8. What is OpenAI's maximum breach-notification window for ChatGPT Enterprise customers, what deletion SLA applies after termination, and what advance notice and deprecation period apply when the models available to a ChatGPT Enterprise workspace change?
9. Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.
10. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
11. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
12. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Explicit no-training default and admin-controlled retention for ChatGPT EnterpriseStrong

OpenAI commits, by name, that ChatGPT Enterprise data is not used to train its models by default (the only exception is explicit customer opt-in), extends the same commitment to data reached through connected apps, gives workspace admins control over retention with deleted conversations purged within 30 days, and limits OpenAI staff access to incident resolution, customer-authorised recovery or legal compulsion. Consumer-service training language in the Privacy Policy is expressly carved away from business offerings.

These are the core data-handling questions for any ChatGPT Enterprise purchase, and they are answered in the vendor's own words with the product named, rather than inferred from generic policy. Buyers should still confirm the opt-in feedback mechanisms are disabled or controlled at workspace level.

Question for vendor: Can workspace administrators disable or centrally control the opt-in feedback/data-sharing mechanisms for all users in a ChatGPT Enterprise workspace?

Evidence
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“​​Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
✓Named, product-scoped sub-processor register and ChatGPT Enterprise-scoped ISO 27001 / SOC 2Strong

The public Sub-processor list (9 July 2026) names each third party, the products it serves (ChatGPT Enterprise is listed per row) and the processing countries, and the DPA binds OpenAI to notify changes with a 30-day objection right. The ISO/IEC 27001:2022 certificate announcement names ChatGPT Enterprise in scope (with 27017/27018/27701), the 2025 SOC 2 report scope names ChatGPT Enterprise, and a public bug bounty with safe harbour operates.

A per-product sub-processor register plus certifications whose published scope names the assessed product is uncommon; it lets a buyer map the processing chain and rely on assurance that actually covers ChatGPT Enterprise rather than the organisation at large. All of this remains vendor-published until checked against the registries.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Externally corroboratedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“What compliance standards do ChatGPT Enterprise, ChatGPT Edu, and ChatGPT for Healthcare meet? They’ve each successfully completed a SOC 2 Type 2 audit.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via our Bug Bounty Program. The program offers safe harbor for good faith security testing and cash rewards for vulnerabilities based on their severity and impact.”
!Processing spans many countries and offshore support; residency commitment for Enterprise not in the collectionGap

Infrastructure sub-processors for ChatGPT Enterprise process in 20+ countries (Microsoft alone lists 23), Cloudflare processes at the data centre nearest the end user, TaskUs provides support and GPT moderation from the Philippines, flagged content samples may be shared with moderation sub-processors, and EEA data may leave the EEA under SCCs. OpenAI's security page references data residency for ChatGPT but the residency terms themselves were not retrievable here.

For regulated or government buyers (for example APRA CPS 234 or Australian government data), knowing which region a workspace is pinned to, and whether support and moderation staff outside that region can see content, is a contractual question the public pages do not settle.

Question for vendor: Which processing regions can a ChatGPT Enterprise workspace be pinned to, does residency cover both at-rest storage and inference, and are TaskUs/Accenture support or moderation personnel able to access workspace content outside the selected region?

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
!Several Trust Portal badges lack public scope, issuer or validity; some do not cover ChatGPT EnterpriseGap

The portal lists SOC 3, TX-RAMP and FedRAMP 20x without any scope or status statement; PCI DSS is explicitly scoped to ChatGPT's delegated payment-processing components, not Enterprise controls; ISO/IEC 42001 is described as covering 'consumer and business AI products and models' without naming the product or certification body; CSA STAR is Level 1, a self-assessment; and the 2026 SOC 2 report's in-scope products are deferred to a compliance-status page outside this collection. No certification body or SOC 2 auditor is named anywhere in the public pages.

Badge lists invite buyers to assume every item covers the product they are buying. Here only ISO 27001 (and its extensions) and the 2025 SOC 2 scope explicitly name ChatGPT Enterprise; the rest need the certificate or report itself, which sits behind the gated portal.

Question for vendor: Please provide the ISO/IEC 27001 and 42001 certificates (issuer, certificate number, validity, scope statement), the 2026 SOC 2 Type 2 report with its system description, and the FedRAMP 20x authorisation status as they apply to ChatGPT Enterprise.

Evidence
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“Compliance SOC 2 Type 2 SOC 3 PCI DSS v4.0.1 ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 ISO/IEC 42001:2023 CCPA CSA STAR GDPR TX-RAMP FedRAMP 20x”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions.”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“ChatGPT business product services and the API Platform have been evaluated by the Cloud Security Alliance Security Trust Assurance and Risk (STAR) registry for key principles of transparency and cloud security best practices.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI's most recent SOC2 Report covers the period of July 1, 2025 to June 30, 2026 and is now available to authenticated users on the OpenAI Trust Portal. This report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria. View OpenAI products and services in scope at the OpenAI Product Compliance Status page”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
!No fixed breach-notification window and no published model-change notice for ChatGPT EnterpriseGap

The DPA commits to breach notification 'without undue delay' but states no hours-based window, and the end-of-contract deletion clause gives no timeline. On change management, the only contractual notice commitment is for sub-processor changes; model changes reach Enterprise via public release notes and admin enablement, with no stated notice period or deprecation policy for the models serving the product. Testing and evaluation evidence is organisation-level (benchmarks, adversarial testing); no ChatGPT Enterprise-specific evaluation or system card is in the collection. All domains are assessed as covered or partial rather than not_evidenced: as a hosted service every domain applies, and OpenAI publishes at least some disclosure in each.

Enterprises with regulatory notification duties (GDPR 72 hours, APRA CPS 234 72 hours) need the processor's window to be shorter than their own, and change-control programs need advance notice of model swaps that can alter output behaviour across a workspace.

Question for vendor: What is OpenAI's maximum breach-notification window for ChatGPT Enterprise customers, what deletion SLA applies after termination, and what advance notice and deprecation period apply when the models available to a ChatGPT Enterprise workspace change?

Evidence
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
Externally corroboratedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Our models and systems are regularly evaluated through evaluations against industry benchmarks, adversarial testing and ongoing safety monitoring.”
?Technical dependency observed: IntercomObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score45
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Within your organization, end users can view their own conversations. Your organization has control over workspaces, and workspace admins can access an audit log of conversations and GPTs through the Enterprise Compliance API⁠”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
Externally corroboratedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
AI system15% of the score40
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Built for businesses, ChatGPT Enterprise offers organizations the ability to use ChatGPT with controls, deployment tools, and speed required to make your entire organization more productive.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Our models and systems are regularly evaluated through evaluations against industry benchmarks, adversarial testing and ongoing safety monitoring.”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Externally corroboratedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedRelease Notes | OpenAI | OpenAI ↗retrieved Oct 5, 2026
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Customer data15% of the score70
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“​​Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“We may run any business data submitted to OpenAI’s services through automated content classifiers and safety tools, including to better understand how our services are used. The classifications created are metadata about the business data but do not contain any of the business data itself. Business data is only subject to human review as described below on a service-by-service basis.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI encrypts all data at rest (AES-256) and in transit between our customers and us and between us and our service providers (TLS 1.2+), and uses strict access controls to limit who can access data.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
Externally corroboratedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center ⁠ (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
Vendor publishedOpenAI Sub-processor list | OpenAI ↗retrieved Oct 5, 2026
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
Externally corroboratedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via our Bug Bounty Program. The program offers safe harbor for good faith security testing and cash rewards for vulnerabilities based on their severity and impact.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score59
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“What compliance standards do ChatGPT Enterprise, ChatGPT Edu, and ChatGPT for Healthcare meet? They’ve each successfully completed a SOC 2 Type 2 audit.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI's most recent SOC2 Report covers the period of July 1, 2025 to June 30, 2026 and is now available to authenticated users on the OpenAI Trust Portal. This report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria. View OpenAI products and services in scope at the OpenAI Product Compliance Status page”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
Vendor publishedSecurity and privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“ChatGPT business product services and the API Platform have been evaluated by the Cloud Security Alliance Security Trust Assurance and Risk (STAR) registry for key principles of transparency and cloud security best practices.”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“Compliance SOC 2 Type 2 SOC 3 PCI DSS v4.0.1 ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 ISO/IEC 42001:2023 CCPA CSA STAR GDPR TX-RAMP FedRAMP 20x”
Vendor publishedOpenAI Trust Portal | Powered by SafeBase ↗retrieved Oct 5, 2026
“OpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions.”
Registry verifiedCSA STAR Registry record — CSA STAR Level 2 ↗retrieved Oct 5, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedEnterprise privacy at OpenAI | OpenAI ↗retrieved Oct 5, 2026
“Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws.”
Vendor publishedTerms of Use | OpenAI ↗retrieved Oct 5, 2026
“Our Business Terms⁠ ⁠ govern use of ChatGPT Enterprise, our APIs, and our other services for businesses and developers.”
Vendor publishedPrivacy policy | OpenAI ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“(ii) provided that the Parties have an appropriate confidentiality agreement in place, allow for and contribute to audits or inspections by, or on behalf of, Customer at Customer’s sole expense.  Such audit or inspection must be: (A) conducted in a manner that is minimally disruptive to OpenAI’s business; (B) necessary to confirm that OpenAI is processing Customer Data in a manner consistent with this DPA; and (C) occur no more than once per year.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
Vendor publishedOpenAI Data Processing Addendum | OpenAI ↗retrieved Oct 5, 2026
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Have Customer data treatment disclosures independently corroboratedData 70 → 85
+3Complete the Governance & accountability disclosureOrganisation 45 → 65
+3Verify CSA STAR Level 2 scope covers this assessmentIndependent Assurance 59 → 81
+3Verify FedRAMP Authorization scope covers this assessmentIndependent Assurance 59 → 81
+2Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 60 → 75

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 59 → up to 80 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURESUBPROCESSORSOpenAIOpenAIChatGPT EnterpriseChatGPT EnterpriseGPT-6 family (GPT-6 Astra, GPT-6.1 Sol)GPT-6 family (GPT-6 Astra…Microsoft CorporationMicrosoft CorporationCoreWeave, Inc.CoreWeave, Inc.Oracle Cloud InfrastructureOracle Cloud Infrastructu…Google Cloud PlatformGoogle Cloud PlatformAmazon Web Services, Inc.Amazon Web Services, Inc.CerebrasCerebrasCloudflare, Ltd.Cloudflare, Ltd.Snowflake, Inc.Snowflake, Inc.TaskUs, LLCTaskUs, LLC
View as list
ChatGPT Enterprise Uses AI Service GPT-6 family (GPT-6 Astra, GPT-6.1 Sol)
ChatGPT Enterprise Uses Infrastructure Microsoft Corporation
ChatGPT Enterprise Uses Infrastructure CoreWeave, Inc.
ChatGPT Enterprise Uses Infrastructure Oracle Cloud Infrastructure
ChatGPT Enterprise Uses Infrastructure Google Cloud Platform
ChatGPT Enterprise Uses Infrastructure Amazon Web Services, Inc.
ChatGPT Enterprise Uses Infrastructure Cerebras
ChatGPT Enterprise Uses Infrastructure Cloudflare, Ltd.
OpenAI Contracted Subprocessor Microsoft Corporation
OpenAI Contracted Subprocessor CoreWeave, Inc.
OpenAI Contracted Subprocessor Oracle Cloud Infrastructure
OpenAI Contracted Subprocessor Google Cloud Platform
OpenAI Contracted Subprocessor Amazon Web Services, Inc.
OpenAI Contracted Subprocessor Cerebras
OpenAI Contracted Subprocessor Cloudflare, Ltd.
OpenAI Contracted Subprocessor Snowflake, Inc.
OpenAI Contracted Subprocessor TaskUs, LLC

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 13 — registry checks and verification ladders, click to view
SOC 2 Type 2Vendor claimed only

Enterprise privacy page states ChatGPT Enterprise, ChatGPT Edu and ChatGPT for Healthcare each completed a SOC 2 Type 2 audit. 2025 report (1 Jan-30 Jun 2025) covered Security, Availability, Confidentiality and Privacy TSC for API Platform, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Team. 2026 report covers 1 Jul 2025-30 Jun 2026; its product scope is deferred to a compliance-status page not in this collection. Auditor not named.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SOC 3Claimed, scope unclear

Listed as a Trust Portal compliance item and gated report; no scope, period or auditor stated publicly.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001:2022Vendor claimed only

Certificate stated to cover the ISMS for OpenAI's API, ChatGPT Enterprise and ChatGPT Edu services and to be publicly viewable on trust.openai.com. Certification body and validity not stated in the announcement.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27017:2015Vendor claimed only

Stated as an additional control set within the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018:2019Vendor claimed only

Stated as an additional control set within the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27701:2019Vendor claimed only

PIMS extension stated to be included in the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001:2023Vendor claimed only

Stated to cover OpenAI's consumer and business AI products and models as AI producer and AI provider; ChatGPT Enterprise not named, certification body and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

CSA STAR Level 1Vendor claimed only

ChatGPT business product services and the API Platform listed in the CSA STAR registry. Level 1 is a self-assessment (CAIQ), not third-party certification; CAIQ listed as a gated self-assessment document on the Trust Portal.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

PCI DSS v4.0.1Vendor claimed only

Scoped to the components of ChatGPT that support delegated payment processing for merchant transactions; not a control attestation over ChatGPT Enterprise.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

TX-RAMPClaimed, scope unclear

Listed as a Trust Portal compliance item only; certification level, products and status not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

FedRAMP 20xClaimed, scope unclear

Listed as a Trust Portal compliance item with gated package documents; authorisation status, impact level and in-scope products not stated publicly.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Oct 5, 2026: Verified on the registry

Sources 18 — click to view
OpenAI Trust Portal | Powered by SafeBase
Subprocessor List · Vendor · retrieved Oct 5, 2026
Blog | OpenAI Developers
Technical Article · Vendor · retrieved Oct 5, 2026
OpenAI Trust Portal | Powered by SafeBase
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Using tools | OpenAI API
Product Documentation · Vendor · retrieved Oct 5, 2026
Production best practices | OpenAI API
Product Documentation · Vendor · retrieved Oct 5, 2026
Enterprise privacy at OpenAI | OpenAI
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Usage policies | OpenAI
Terms · Vendor · retrieved Oct 5, 2026
Security and privacy at OpenAI | OpenAI
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
OpenAI | Research & Deployment
AI Documentation · Vendor · retrieved Oct 5, 2026
OpenAI Data Processing Addendum | OpenAI
DPA · Vendor · retrieved Oct 5, 2026
OpenAI Sub-processor list | OpenAI
Subprocessor List · Vendor · retrieved Oct 5, 2026
Privacy policy | OpenAI
Privacy Notice · Vendor · retrieved Oct 5, 2026
Compliance Horizon Scanner plugin for ChatGPT | OpenAI
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Terms of Use | OpenAI
Terms · Vendor · retrieved Oct 5, 2026
Release Notes | OpenAI | OpenAI
Changelog Or Release Notes · Vendor · retrieved Oct 5, 2026
How AI-native companies turn workflows into operating capability | OpenAI
AI Documentation · Vendor · retrieved Oct 5, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.