ted by an independent third-party auditor to confirm that our controls align with industry standards for security, confidentiality, privacy and availability. Our products are also ISO 27001, 27017, 27018, and 27701 certified. Request access to our SOC 2 Report below to learn more about our security controls and compliance activities. OpenAI invites security researchers, ethical hackers, and technology enthusiasts to report security issues via ou
View source ↗OpenAI SOC 2 status and provider evidence
Review OpenAI’s public SOC 2 statement, report type, evidence source, and freshness.
OpenAI’s SOC 2 stack
No provider is named on the current source.
We will update this page if the company publishes more detail.
Frameworks named by OpenAI
nd services in scope at the OpenAI Product Compliance Status page. Customers with active trust.openai.com accounts can access the latest report under "Compliance" > "SOC 2 Type 2."PCI DSSCopy linkComplianceOpenAI now maintains PCI-DSS compliance for the components of ChatGPT that support delegated payment processing, ensuring secure handling of payment information for supported merchant transactions. Customers may view relevant documentati
View source ↗OpenAI's 2026 SOC 2 Type 2 Report is now available to customers at trust.openai.com.Trust PortalStart your security reviewView & download sensitive informationGet accessOverviewWelcome to our Trust Portal for OpenAI's ChatGPT services, including ChatGPT Enterprise and ChatGPT
View source ↗Primary compliance evidence
OpenAI's 2026 SOC 2 Type 2 Report is now available to customers at trust.openai.com.Trust PortalStart your security reviewView & download sensitive informationGet accessOverviewWelcome to our Trust Portal for OpenAI's ChatGPT services, including ChatGPT Enterprise and ChatGPT Edu. He
Open source ↗