
Summary
OpenAI has 2 registry-verified rows and 11 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is SOC 2: Vendor states SOC 2 Type 2 on its trust centre. This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, OpenAI states on its trust centre that it holds a SOC 2 Type II report, with no independent registry confirmation provided in these rows. As of 9 Jan 2026, OpenAI is listed in the FedRAMP registry as FedRAMP Authorized, with the authorization audited by Schellman Compliance, LLC. As of 9 Apr 2024, OpenAI is listed in the CSA STAR registry with a STAR Level 1 self-assessment (CAIQ) on file. As of 17 Sep 2026, OpenAI states on its trust centre that it holds ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, and ISO/IEC 42001, and also states GDPR, PCI DSS, SOC 3, CCPA / CPRA, and TX-RAMP coverage on its trust centre as of the same date. No public evidence of a HIPAA BAA was found in these rows as of 17 Sep 2026, and the evidence includes a public subprocessor list of 13 entities as of 17 Sep 2026.
- SOC 2: vendor states on its trust centre it holds a SOC 2 Type II report (as of 17 Sep 2026); FedRAMP: listed in FedRAMP registry as Authorized, audited by Schellman Compliance, LLC (issued 9 Jan 2026, as of 17 Sep 2026).
- CSA STAR: listed in CSA STAR registry with a Level 1 self-assessment (CAIQ) (issued 9 Apr 2024, as of 17 Sep 2026); ISO/IEC 27001, 27701, 27017, 27018, 42001: vendor states on its trust centre (as of 17 Sep 2026).
- HIPAA: no public evidence found in these rows (as of 17 Sep 2026); subprocessors: public list of 13 subprocessors disclosed (as of 17 Sep 2026).
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among ai infrastructure vendors
2verified rows
Category median 1, across 39 indexed ai infrastructure vendors. OpenAI has more verified rows than 100 percent of them.
ai-platformapifoundation-modelsgptllm
Compare with similar vendors
Pick your own comparisonCompliance grid
SOC 2Vendor-statedVendor states SOC 2 Type 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source - FedRAMPVerified
FedRAMP Authorized
as of 17 Sep 20261 source · Schellman Compliance, LLC
PCI DSSVendor-statedVendor states PCI DSS on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27001Vendor-statedVendor states ISO 27001 on its trust centre
as of 17 Sep 20261 source- CSA STARVerified
STAR Level 1 self-assessment (CAIQ)
as of 17 Sep 20261 source
ISO/IEC 27701Vendor-statedVendor states ISO/IEC 27701:2019 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 42001Vendor-statedVendor states ISO/IEC 42001:2023 on its trust centre
as of 17 Sep 20261 source
SOC 3Vendor-statedVendor states SOC 3 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27017Vendor-statedVendor states ISO/IEC 27017:2015 on its trust centre
as of 17 Sep 20261 source
ISO/IEC 27018Vendor-statedVendor states ISO/IEC 27018:2019 on its trust centre
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
TX-RAMPVendor-statedVendor states TX-RAMP on its trust centre
as of 17 Sep 20261 source
No public evidence yet for HIPAA, Cyber Essentials. This does not mean the vendor lacks them; it means nothing public was found at the last check.
Legal artefacts
Subprocessors (13)
- COCompliance OpenAI
- CFCriteria for the API Platform
- F2FedRAMP 20x OpenAI
- ISInfrastructure Status Monitoring Cloud
- PDPCI DSS Compliance OpenAI
- PTPrivacy Trust Services
- PTPrivacy Trust Services Criteria. View OpenAI
- SCSupply Chain Risk Management FedRAMP 20x OpenAI
- T2The 2025 SOC2 Report for OpenAI
- TCThis certificate documents OpenAI
- TCTrust Center and Documentation OpenAI
- VMView more Trust Portal Updates Subscribe OpenAI
- WAWe are excited to announce that OpenAI
Change history
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 27701 evidence addedA ISO/IEC 27701 row entered the index with state Vendor-stated.
- 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
- 17 Sep 2026PCI DSS evidence addedA PCI DSS row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 3 evidence addedA SOC 3 row entered the index with state Vendor-stated.
Similar vendors with evidence
Related by product tags and the AI infrastructure category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.