Skip to main content
OpenAI logo

OpenAI

PCI DSS evidence

openai.comAI infrastructureLast verified 17 Sep 2026
PCI DSS mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

OpenAI and PCI DSS

OpenAI states it holds a PCI DSS attestation of compliance. CertReports captured this on 17 Sep 2026 from its trust centre (Drata); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
OpenAI trust centre (Drata)
Vendor trust centre · HTTP 200
17 Sep 2026PCI DSS
Live page Snapshotsha256 bdacda3d9f
What PCI DSS means, and what it does not

Only a registry listing (Visa Global Registry, Mastercard SDP) or an AOC letter is strong evidence. In the Visa registry only rows validated as PCI DSS with a validation date count; Third Party Agent registrations are not PCI evidence.

Read the PCI DSS guide and browse all vendors with evidence

Questions buyers ask

Is OpenAI PCI DSS compliant?

OpenAI is listed as a PCI DSS validated service provider, as of 17 Sep 2026.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.

Alternatives with PCI DSS evidence

Similar vendors (shared product tags or the AI infrastructure category) whose PCI DSS row is verified or vendor-stated, ranked by similarity.