SOC 2 company profile

OpenAI SOC 2 status and provider evidence

Review OpenAI’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeType II
Providers found0
Last checked2026-08-31
Providers

OpenAI’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Compliance coverage

Frameworks named by OpenAI

ISO 27001

ted by an independent third-party auditor to confirm that our controls align with industry standards for security, confidentiality, privacy and availability. Our products are also ISO 27001, 27017, 27018, and 27701 certified. Request access to our SOC 2 Report below to learn more about our security controls and compliance activities. OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via ou

Checked 2026-08-31
View source ↗
PCI DSS

nd services in scope at the OpenAI Product Compliance Status page. Customers with active trust.openai.com accounts can access the latest report under "Compliance" > "SOC 2 Type 2."PCI DSSCopy linkComplianceOpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions. Customers may view relevant documentati

Checked 2026-08-31
View source ↗
SOC 2

OpenAI's 2026 SOC 2 Type 2 Report is now available to customers at trust.openai.com.Trust PortalStart your security reviewView & download sensitive informationGet access​​OverviewWelcome to our Trust Portal for OpenAI's ChatGPT services, including ChatGPT Enterprise and ChatGPT

Checked 2026-08-31
View source ↗

Primary compliance evidence

OpenAI public statement

OpenAI's 2026 SOC 2 Type 2 Report is now available to customers at trust.openai.com.Trust PortalStart your security reviewView & download sensitive informationGet access​​OverviewWelcome to our Trust Portal for OpenAI's ChatGPT services, including ChatGPT Enterprise and ChatGPT Edu. He

Classification: self attested · checked 2026-08-31
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement