Is this your company? Buyers are checking OpenAI here. Claim openai.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
OpenAI
Sourced from public information. Not yet verified by the company.
OpenAI is SOC 2 Type II compliant, with its most recent report dated Jun 2025. OpenAI also holds SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, PCI DSS, GDPR, CCPA, FedRAMP, and CSA STAR.
About
AI research and deployment company; ChatGPT and the API platform.
Compliance & infrastructure
Compliance leadership
The person who leads OpenAI's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. OpenAI's penetration test vendor isn't listed yet.
Claim this profile to add it.
Recent updates
PCI DSSMar 2026
OpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions. Customers may view relevant documentation at trust.openai.com.
OpenAI's ISO/IEC 27001 Certificate is now available at trust.openai.comAug 2025
We are excited to announce that OpenAI has received an ISO/IEC 27001 Certificate, available for public viewing at trust.openai.com under "Documents." This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services. Control implementation also conforms to additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019 and extends to include the PIMS requirements, control implementation guidance, and additional control set of ISO/IEC 27701:2019.
The 2025 SOC2 Report for OpenAI's ChatGPT Business Products and API is now available to customers at trust.openai.comAug 2025
OpenAI's most recent SOC2 Report covers the period of January 1, 2025 to June 30, 2025 and is now available for viewing on the ChatGPT Business Products and API Trust Portal pages. We are proud to share that this report covered controls relevant to the Security, Availability, Confidentiality, and Privacy Trust Services Criteria for the API Platform, ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team. Customers with active trust.openai.com accounts can access the latest report under "Documents."
Read our latest LLM safety and security publication: "Detecting misbehavior in frontier reasoning models"Mar 2025
Frontier reasoning models exploit loopholes when given the chance. We show we can detect exploits using an LLM to monitor their chains-of-thought. Penalizing their “bad thoughts” doesn’t stop the majority of misbehavior—it makes them hide their intent. Read more on our blog!
OpenAI Publishes the o3-mini, Deep Research, and GPT 4.5 System CardsMar 2025
System Cards for the recently released o3-mini, Deep Research, and GPT 4.5 models are now accessible to the public. System Cards detail our safety work on recently released models and are updated on our Security Portal for our customers’ reference.
OpenAI Publishes the GPT-4o and OpenAI o1 System CardsSep 2024
The GPT-4o and OpenAI o1 System Cards detail our safety work on recently released models and are now available on our Trust Portal for our customers’ reference. The GPT-4o System Card outlines the safety work carried out prior to releasing GPT-4o including external red teaming, frontier risk evaluations according to our Preparedness Framework, and an overview of the mitigations we built in to address key risk areas. The OpenAI o1 System Card outlines the safety work carried out prior to releasing OpenAI o1-preview and o1-mini, including external red teaming and frontier risk evaluations according to our Preparedness Framework.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- DocumentsList the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
- SubprocessorsList your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
