Skip to main content
OpenAI logo

OpenAI

Security and trust center evidence

openai.comAI infrastructureLast verified 17 Sep 2026

Summary

OpenAI has 2 registry-verified rows and 11 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, OpenAI states on its trust centre that it holds a SOC 2 Type II report, with no independent registry confirmation provided in these rows. As of 9 Jan 2026, OpenAI is listed in the FedRAMP registry as FedRAMP Authorized, with the authorization audited by Schellman Compliance, LLC. As of 9 Apr 2024, OpenAI is listed in the CSA STAR registry with a STAR Level 1 self-assessment (CAIQ) on file. As of 17 Sep 2026, OpenAI states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, and ISO/IEC 42001, and also states GDPR, PCI DSS, SOC 3, CCPA / CPRA, and TX-RAMP coverage on its trust centre as of the same date. No public evidence of a HIPAA BAA was found in these rows as of 17 Sep 2026, and the evidence includes a public subprocessor list of 13 entities as of 17 Sep 2026.

  • SOC 2: vendor states on its trust centre it holds a SOC 2 Type II report (as of 17 Sep 2026); FedRAMP: listed in FedRAMP registry as Authorized, audited by Schellman Compliance, LLC (issued 9 Jan 2026, as of 17 Sep 2026).
  • CSA STAR: listed in CSA STAR registry with a Level 1 self-assessment (CAIQ) (issued 9 Apr 2024, as of 17 Sep 2026); ISO/IEC 27001, 27701, 27017, 27018, 42001: vendor states on its trust centre (as of 17 Sep 2026).
  • HIPAA: no public evidence found in these rows (as of 17 Sep 2026); subprocessors: public list of 13 subprocessors disclosed (as of 17 Sep 2026).

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among ai infrastructure vendors

2verified rows

Category median 1, across 39 indexed ai infrastructure vendors. OpenAI has more verified rows than 100 percent of them.

ai-platformapifoundation-modelsgptllm

Compliance grid

Subprocessors (13)

  • CO
    Compliance OpenAI
  • CF
    Criteria for the API Platform
  • F2
    FedRAMP 20x OpenAI
  • IS
    Infrastructure Status Monitoring Cloud
  • PD
    PCI DSS Compliance OpenAI
  • PT
    Privacy Trust Services
  • PT
    Privacy Trust Services Criteria. View OpenAI
  • SC
    Supply Chain Risk Management FedRAMP 20x OpenAI
  • T2
    The 2025 SOC2 Report for OpenAI
  • TC
    This certificate documents OpenAI
  • TC
    Trust Center and Documentation OpenAI
  • VM
    View more Trust Portal Updates Subscribe OpenAI
  • WA
    We are excited to announce that OpenAI

Change history

  1. 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
  2. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  3. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  4. 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
  5. 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
  6. 17 Sep 2026ISO/IEC 27701 evidence addedA ISO/IEC 27701 row entered the index with state Vendor-stated.
  7. 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
  8. 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
  9. 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
  10. 17 Sep 2026SOC 3 evidence addedA SOC 3 row entered the index with state Vendor-stated.

Similar vendors with evidence

Related by product tags and the AI infrastructure category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.