ChatGPT Enterprise
openai.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No clear commitment that your data will not train their models
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Oct 5, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
OpenAI's consumer Privacy Policy states that content provided by individual users may be used to improve its services, including to train the models that power ChatGPT, subject to an opt-out. This applies to OpenAI's services for individuals (ChatGPT Free/Plus/Pro and similar), not to business offerings such as ChatGPT Enterprise.
Requires written confirmation — see Before you sign ↓
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
!How long do they keep your data?Ask the vendor
For ChatGPT Enterprise (and Edu and for Healthcare), workspace administrators control how long data is retained, and deleted conversations are removed from OpenAI's systems within 30 days unless legal retention obligations apply.
Requires written confirmation — see Before you sign ↓
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”
!Who else can access your data?Ask the vendor
OpenAI's Sub-processor list (updated 9 July 2026) names Microsoft Corporation as a cloud infrastructure sub-processor for the API, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Business, with processing locations across 23 countries including Australia, Ireland, the United Kingdom, Japan, Singapore and the United States.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
!Where is your data processed?Ask the vendor
The DPA instructs OpenAI Ireland Limited to process EEA and Swiss data and discloses that such data may be transferred to other OpenAI affiliates or third parties outside the EEA/Switzerland to provide the Services, relying on Standard Contractual Clauses or an EU adequacy decision. UK data is handled under the SCCs with the UK Addendum.
Confirm in writing: Ask the vendor to state this in writing before signing.
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
!What happens in a security incident?Ask the vendor
OpenAI's security team operates a 24/7/365 on-call rotation that is paged for any potential security incident.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident.”
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”
Email to send the vendor12 items to confirm in writing
Hello OpenAI team, We are assessing ChatGPT Enterprise (OpenAI) as part of our supplier review. Before we proceed, please confirm the following in writing: 1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan. 2. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted? 3. Please provide your current, dated subprocessor list and explain how you notify customers of changes. 4. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose? 5. What is your commitment to notify customers of a security incident affecting our data, including the timeframe? 6. Can workspace administrators disable or centrally control the opt-in feedback/data-sharing mechanisms for all users in a ChatGPT Enterprise workspace? 7. Please provide the ISO/IEC 27001 and 42001 certificates (issuer, certificate number, validity, scope statement), the 2026 SOC 2 Type 2 report with its system description, and the FedRAMP 20x authorisation status as they apply to ChatGPT Enterprise. 8. What is OpenAI's maximum breach-notification window for ChatGPT Enterprise customers, what deletion SLA applies after termination, and what advance notice and deprecation period apply when the models available to a ChatGPT Enterprise workspace change? 9. Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data. 10. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. 11. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. 12. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date. Thank you,
Key findingsclick a row for the evidence
✓Explicit no-training default and admin-controlled retention for ChatGPT EnterpriseStrong
OpenAI commits, by name, that ChatGPT Enterprise data is not used to train its models by default (the only exception is explicit customer opt-in), extends the same commitment to data reached through connected apps, gives workspace admins control over retention with deleted conversations purged within 30 days, and limits OpenAI staff access to incident resolution, customer-authorised recovery or legal compulsion. Consumer-service training language in the Privacy Policy is expressly carved away from business offerings.
These are the core data-handling questions for any ChatGPT Enterprise purchase, and they are answered in the vendor's own words with the product named, rather than inferred from generic policy. Buyers should still confirm the opt-in feedback mechanisms are disabled or controlled at workspace level.
Question for vendor: Can workspace administrators disable or centrally control the opt-in feedback/data-sharing mechanisms for all users in a ChatGPT Enterprise workspace?
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
“Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.”
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
“This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.”
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
✓Named, product-scoped sub-processor register and ChatGPT Enterprise-scoped ISO 27001 / SOC 2Strong
The public Sub-processor list (9 July 2026) names each third party, the products it serves (ChatGPT Enterprise is listed per row) and the processing countries, and the DPA binds OpenAI to notify changes with a 30-day objection right. The ISO/IEC 27001:2022 certificate announcement names ChatGPT Enterprise in scope (with 27017/27018/27701), the 2025 SOC 2 report scope names ChatGPT Enterprise, and a public bug bounty with safe harbour operates.
A per-product sub-processor register plus certifications whose published scope names the assessed product is uncommon; it lets a buyer map the processing chain and rely on assurance that actually covers ChatGPT Enterprise rather than the organisation at large. All of this remains vendor-published until checked against the registries.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
“What compliance standards do ChatGPT Enterprise, ChatGPT Edu, and ChatGPT for Healthcare meet? They’ve each successfully completed a SOC 2 Type 2 audit.”
“OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via our Bug Bounty Program. The program offers safe harbor for good faith security testing and cash rewards for vulnerabilities based on their severity and impact.”
!Processing spans many countries and offshore support; residency commitment for Enterprise not in the collectionGap
Infrastructure sub-processors for ChatGPT Enterprise process in 20+ countries (Microsoft alone lists 23), Cloudflare processes at the data centre nearest the end user, TaskUs provides support and GPT moderation from the Philippines, flagged content samples may be shared with moderation sub-processors, and EEA data may leave the EEA under SCCs. OpenAI's security page references data residency for ChatGPT but the residency terms themselves were not retrievable here.
For regulated or government buyers (for example APRA CPS 234 or Australian government data), knowing which region a workspace is pinned to, and whether support and moderation staff outside that region can see content, is a contractual question the public pages do not settle.
Question for vendor: Which processing regions can a ChatGPT Enterprise workspace be pinned to, does residency cover both at-rest storage and inference, and are TaskUs/Accenture support or moderation personnel able to access workspace content outside the selected region?
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
!Several Trust Portal badges lack public scope, issuer or validity; some do not cover ChatGPT EnterpriseGap
The portal lists SOC 3, TX-RAMP and FedRAMP 20x without any scope or status statement; PCI DSS is explicitly scoped to ChatGPT's delegated payment-processing components, not Enterprise controls; ISO/IEC 42001 is described as covering 'consumer and business AI products and models' without naming the product or certification body; CSA STAR is Level 1, a self-assessment; and the 2026 SOC 2 report's in-scope products are deferred to a compliance-status page outside this collection. No certification body or SOC 2 auditor is named anywhere in the public pages.
Badge lists invite buyers to assume every item covers the product they are buying. Here only ISO 27001 (and its extensions) and the 2025 SOC 2 scope explicitly name ChatGPT Enterprise; the rest need the certificate or report itself, which sits behind the gated portal.
Question for vendor: Please provide the ISO/IEC 27001 and 42001 certificates (issuer, certificate number, validity, scope statement), the 2026 SOC 2 Type 2 report with its system description, and the FedRAMP 20x authorisation status as they apply to ChatGPT Enterprise.
“Compliance SOC 2 Type 2 SOC 3 PCI DSS v4.0.1 ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 ISO/IEC 42001:2023 CCPA CSA STAR GDPR TX-RAMP FedRAMP 20x”
“OpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions.”
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
“ChatGPT business product services and the API Platform have been evaluated by the Cloud Security Alliance Security Trust Assurance and Risk (STAR) registry for key principles of transparency and cloud security best practices.”
“OpenAI's most recent SOC2 Report covers the period of July 1, 2025 to June 30, 2026 and is now available to authenticated users on the OpenAI Trust Portal. This report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria. View OpenAI products and services in scope at the OpenAI Product Compliance Status page”
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
!No fixed breach-notification window and no published model-change notice for ChatGPT EnterpriseGap
The DPA commits to breach notification 'without undue delay' but states no hours-based window, and the end-of-contract deletion clause gives no timeline. On change management, the only contractual notice commitment is for sub-processor changes; model changes reach Enterprise via public release notes and admin enablement, with no stated notice period or deprecation policy for the models serving the product. Testing and evaluation evidence is organisation-level (benchmarks, adversarial testing); no ChatGPT Enterprise-specific evaluation or system card is in the collection. All domains are assessed as covered or partial rather than not_evidenced: as a hosted service every domain applies, and OpenAI publishes at least some disclosure in each.
Enterprises with regulatory notification duties (GDPR 72 hours, APRA CPS 234 72 hours) need the processor's window to be shorter than their own, and change-control programs need advance notice of model swaps that can alter output behaviour across a workspace.
Question for vendor: What is OpenAI's maximum breach-notification window for ChatGPT Enterprise customers, what deletion SLA applies after termination, and what advance notice and deprecation period apply when the models available to a ChatGPT Enterprise workspace change?
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
“Our models and systems are regularly evaluated through evaluations against industry benchmarks, adversarial testing and ongoing safety monitoring.”
?Technical dependency observed: IntercomObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score45
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“Within your organization, end users can view their own conversations. Your organization has control over workspaces, and workspace admins can access an audit log of conversations and GPTs through the Enterprise Compliance API”
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
AI system15% of the score40
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Built for businesses, ChatGPT Enterprise offers organizations the ability to use ChatGPT with controls, deployment tools, and speed required to make your entire organization more productive.”
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Our models and systems are regularly evaluated through evaluations against industry benchmarks, adversarial testing and ongoing safety monitoring.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Model10% of the score40
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“GPT-6.1 Sol in Codex, ChatGPT Work, and the API GPT‑6.1 Sol offers near-Astra performance for complex work at a lower cost than Astra. Consider it for repeated, long-running work across code, apps, and documents. Availability depends on your plan, client, and workspace settings.”
Customer data15% of the score70
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“By default, data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services.”
“Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
“Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.”
“We may run any business data submitted to OpenAI’s services through automated content classifiers and safety tools, including to better understand how our services are used. The classifications created are metadata about the business data but do not contain any of the business data itself. Business data is only subject to human review as described below on a service-by-service basis.”
“OpenAI encrypts all data at rest (AES-256) and in transit between our customers and us and between us and our service providers (TLS 1.2+), and uses strict access controls to limit who can access data.”
“Following expiry or termination of the Agreement, OpenAI will, at Customer’s instruction, return or delete Customer Data, and existing copies unless retention of Customer Data is required under applicable laws, in which case OpenAI will isolate and protect it from any further processing except to the extent required by applicable laws.”
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
“For content that OpenAI’s models flag as being in violation of OpenAI’s policies, OpenAI may share samples of the flagged Customer Content with relevant Sub-processors to assist OpenAI in its review and enforcement. Sharing with the Sub-processor platform only occurs when content is flagged, the Sub-processor platform only retains samples of content for the period of review, and OpenAI’s Sub-processors only process the content to assist OpenAI in its review.”
“Apps enable ChatGPT to send and retrieve information from connected internal sources and third-party applications, including to help provide more context for its responses. Your workspace admins can control which apps are enabled for your workspace. ChatGPT respects your organization’s existing permissions, and each end user is required to authenticate with a connected application before use. By default, we do not train our models on any data accessed from apps.”
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
“OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case.”
Customer data treatment: vendor-evidenced, not yet independently corroborated.
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Microsoft Corporation API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Australia Brazil Canada France Germany India Indonesia Ireland Italy Japan Mexico Netherlands Norway Poland Singapore South Africa South Korea Spain Sweden Switzerland United Arab Emirates United Kingdom United States Cloud infrastructure”
“CoreWeave, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Norway Spain Sweden United Kingdom United States Cloud infrastructure Oracle Cloud Infrastructure API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Brazil Japan Malaysia Netherlands United Kingdom United States Cloud infrastructure Google Cloud Platform API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Finland Japan Netherlands Norway United Kingdom United States Cloud infrastructure Amazon Web Services, Inc. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Cloud infrastructure Cerebras API ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Canada Cloud infrastructure”
“Snowflake, Inc. API* ChatGPT Enterprise ChatGPT Edu ChatGPT Business United States Data warehousing”
“Cloudflare, Ltd. API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Processing is performed at the data center (opens in a new window) that is closest to the End User Content delivery network provider Web Hosting”
“TaskUs, LLC API ChatGPT Enterprise ChatGPT Edu ChatGPT Business Philippines All Services : Customer support API & ChatGPT Business: Moderation of content ChatGPT Enterprise, Edu & ChatGPT Business : Moderation of GPTs”
“The following OpenAI affiliate companies provide technical and operational support for the Services. We use the Standard Contractual Clauses as a valid transfer mechanism among affiliates.”
“OpenAI will notify Customer of any changes to the Sub-Processor List via blog post, notification within the Services or other reasonable means, or via email if Customer subscribes to email notifications on the Sub-Processor List site. Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting [email protected].”
Security foundation15% of the score85
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Our security team has an on-call rotation that has 24/7/365 coverage and is paged in case of any potential security incident.”
“OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via our Bug Bounty Program. The program offers safe harbor for good faith security testing and cash rewards for vulnerabilities based on their severity and impact.”
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the score59
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“What compliance standards do ChatGPT Enterprise, ChatGPT Edu, and ChatGPT for Healthcare meet? They’ve each successfully completed a SOC 2 Type 2 audit.”
“This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.”
“OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team.”
“OpenAI's most recent SOC2 Report covers the period of July 1, 2025 to June 30, 2026 and is now available to authenticated users on the OpenAI Trust Portal. This report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria. View OpenAI products and services in scope at the OpenAI Product Compliance Status page”
“OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.”
“ChatGPT business product services and the API Platform have been evaluated by the Cloud Security Alliance Security Trust Assurance and Risk (STAR) registry for key principles of transparency and cloud security best practices.”
“Compliance SOC 2 Type 2 SOC 3 PCI DSS v4.0.1 ISO/IEC 27001:2022 ISO/IEC 27017:2015 ISO/IEC 27018:2019 ISO/IEC 27701:2019 ISO/IEC 42001:2023 CCPA CSA STAR GDPR TX-RAMP FedRAMP 20x”
“OpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws.”
“Our Business Terms govern use of ChatGPT Enterprise, our APIs, and our other services for businesses and developers.”
“This Privacy Policy does not apply to content that we process on behalf of customers of our business offerings, such as our API. Our use of that data is governed by our customer agreements covering access to and use of those offerings.”
“(ii) provided that the Parties have an appropriate confidentiality agreement in place, allow for and contribute to audits or inspections by, or on behalf of, Customer at Customer’s sole expense. Such audit or inspection must be: (A) conducted in a manner that is minimally disruptive to OpenAI’s business; (B) necessary to confirm that OpenAI is processing Customer Data in a manner consistent with this DPA; and (C) occur no more than once per year.”
“To the extent OpenAI Ireland Limited transfers EEA and Swiss Data to other OpenAI Affiliates or third parties outside the European Economic Area or Switzerland to provide the Services, it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission under Article 45 GDPR.”
“OpenAI will notify Customer without undue delay after becoming aware of any Personal Data Breach. OpenAI will provide reasonable assistance to Customer to help Customer comply with its obligations under Data Protection Laws in respect of such Personal Data Breach.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 59 → up to 80 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 13 — registry checks and verification ladders, click to view
Enterprise privacy page states ChatGPT Enterprise, ChatGPT Edu and ChatGPT for Healthcare each completed a SOC 2 Type 2 audit. 2025 report (1 Jan-30 Jun 2025) covered Security, Availability, Confidentiality and Privacy TSC for API Platform, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Team. 2026 report covers 1 Jul 2025-30 Jun 2026; its product scope is deferred to a compliance-status page not in this collection. Auditor not named.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Listed as a Trust Portal compliance item and gated report; no scope, period or auditor stated publicly.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Certificate stated to cover the ISMS for OpenAI's API, ChatGPT Enterprise and ChatGPT Edu services and to be publicly viewable on trust.openai.com. Certification body and validity not stated in the announcement.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Stated as an additional control set within the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Stated as an additional control set within the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
PIMS extension stated to be included in the ISO/IEC 27001 certification covering API, ChatGPT Enterprise and ChatGPT Edu.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Stated to cover OpenAI's consumer and business AI products and models as AI producer and AI provider; ChatGPT Enterprise not named, certification body and validity not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
ChatGPT business product services and the API Platform listed in the CSA STAR registry. Level 1 is a self-assessment (CAIQ), not third-party certification; CAIQ listed as a gated self-assessment document on the Trust Portal.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Scoped to the components of ChatGPT that support delegated payment processing for merchant transactions; not a control attestation over ChatGPT Enterprise.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Listed as a Trust Portal compliance item only; certification level, products and status not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Listed as a Trust Portal compliance item with gated package documents; authorisation status, impact level and in-scope products not stated publicly.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Oct 5, 2026: Verified on the registry
Sources 18 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
Monitor for changes
Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.
