TrustAtlas Procurement Pack
← Full vendor profile   

OpenAI

frontier_builder · United States , San Francisco · founded 2015

Employees: 5000+ · Stage: Series D+ · Funding: $17,900,000,000

18.4
low
default-balanced
composite score

Creator of the GPT model family and ChatGPT, one of the most widely adopted AI platforms globally. Operates as a capped-profit entity under a nonprofit parent.

Analyst summary
OpenAI operates the most widely deployed AI models (GPT-5 family) and has the largest developer ecosystem in the industry. Its enterprise tier is enterprise-grade from a security standpoint, but consumer-tier data handling, training data provenance lawsuits, and deep Microsoft Azure dependency keep it from a clean bill of health.
Safe for most enterprises on the Team or Enterprise tier; treat the consumer tier as unfit for confidential data.
Rating: acceptable

Compliance posture

SOC 2 Type IIYes (report 2025-08-01)
ISO 27001Yes
ISO 42001 (AI management system)No / not disclosed
FedRAMP authorizedNo / not disclosed
GDPR compliantYes
CCPA compliantYes
HIPAA compliantYes
NIST AI RMF alignedYes
CSA STAR certifiedNo / not disclosed
EU AI Act classificationgeneral_purpose

Data handling

Trains on user dataopt_out_available
Outputs feed model improvementopt_out_available
Data retention period30 days
Can delete user data on requestYes (SLA 30 days)
Default data residencyUS
Encryption at restYes (AES-256)
Encryption in transitYes
DPA availableYes
Public subprocessor listYes
HIPAA BAA availableYes

IP profile

User owns outputsyes
Vendor claims output rightsNo / not disclosed
Input IP protectionmoderate
Indemnification offeredYes
Copyright shield programYes
Commercial use permittedYes
Training data provenancepartially_disclosed
Known IP lawsuits6
Multiple lawsuits from authors (NYT, Authors Guild), visual artists, and music publishers regarding training data copyright.

Jurisdiction

Incorporation countryUnited States
Incorporation jurisdiction risklow
Subject to US jurisdictionYes
Subject to EU jurisdictionYes
Subject to China jurisdictionNo / not disclosed
Subject to Russia jurisdictionNo / not disclosed
Government data access riskmoderate
Five Eyes alignedYes
Adequate privacy jurisdictionNo / not disclosed

Governance

Publishes model cardsYes
Publishes transparency reportsYes
Has AI ethics boardYes
Safety testing disclosedYes
Red-teaming programYes
Government contractsYes
Responsible-AI policyhttps://openai.com/safety
Terms of servicehttps://openai.com/policies/terms-of-use
Privacy policyhttps://openai.com/policies/privacy-policy

Incidents on record

DateSeverityIncident
2024-12-30 medium Extended API Outage [source]
2023-03-20 high ChatGPT Chat History Exposure [source]

OWASP LLM Top 10 cross-walk

TrustAtlas dimensions that materially address each OWASP risk. Use to translate this vendor's compliance posture and data-handling stance into the application-security vocabulary your security team already uses.

LLM01
Prompt Injection
User-supplied prompts manipulate model behaviour to bypass intended controls.
SecurityTransparencyDependency chain
LLM02
Sensitive Information Disclosure
Models leak PII, PHI, secrets, or proprietary data through outputs.
Data handlingIP exposureJurisdiction
LLM03
Supply Chain
Risk propagates from upstream models, datasets, plug-ins, and vendors.
Dependency chainBusiness stabilitySecurity
LLM04
Data and Model Poisoning
Adversarial training data or fine-tuning input degrades model integrity.
Data handlingTransparencySecurity
LLM05
Improper Output Handling
Downstream systems blindly trust model output, enabling injection downstream.
IP exposureTransparency
LLM06
Excessive Agency
Agents granted overbroad tool, identity, or permission scopes cause harm.
Dependency chainTransparencyJurisdiction
LLM07
System Prompt Leakage
System prompts containing secrets or logic are extracted via crafted input.
Data handlingTransparency
LLM08
Vector and Embedding Weaknesses
Vector stores and RAG pipelines leak or contaminate retrieved context.
Data handlingSecurity
LLM09
Misinformation
Hallucinated, biased, or fabricated outputs treated as authoritative.
TransparencyRegulatory complianceBusiness stability
LLM10
Unbounded Consumption
Cost, denial-of-service, and resource-exhaustion attacks against LLM endpoints.
SecurityBusiness stability

Full framework reference: https://trustatlas.pages.dev/framework/owasp-llm-top-10

NIST AI RMF cross-walk

How each NIST AI RMF function is supported by the dimensions TrustAtlas scores.

GOVERN
Govern
Establish AI governance structure: policies, roles, accountability.
Regulatory complianceJurisdictionTransparencyBusiness stability
MAP
Map
Establish AI context: intended purpose, use cases, capabilities, and risks.
TransparencyDependency chainData handlingIP exposure
MEASURE
Measure
Quantitative + qualitative risk assessment: testing, benchmarks, monitoring.
SecurityData handlingTransparency
MANAGE
Manage
Treat identified risks: mitigation, controls, incident response, lifecycle.
Regulatory complianceSecurityDependency chainBusiness stability

Full framework reference: https://trustatlas.pages.dev/framework/nist-ai-rmf

Cited sources

FieldSource
data_handling.data_retention_period https://platform.openai.com/docs/models/how-we-use-your-data
Verified 2026-04-19 by admin
data_handling.hipaa_baa_available https://openai.com/enterprise-privacy
Verified 2026-04-19 by admin
data_handling.outputs_feed_model_improvement https://openai.com/enterprise-privacy
Verified 2026-04-19 by admin
data_handling.trains_on_user_data https://openai.com/policies/row-privacy-policy/
Verified 2026-04-19 by admin
ip_profiles.copyright_shield_program https://openai.com/policies/business-terms
Verified 2026-04-19 by admin
ip_profiles.known_ip_lawsuits https://www.nytimes.com/2023/12/27/business/media/new-york-times-open-ai-microsoft-lawsuit.html
Verified 2026-04-19 by admin
ip_profiles.user_owns_outputs https://openai.com/policies/row-terms-of-use/
Verified 2026-04-19 by admin
jurisdiction_profiles.incorporation_country https://openai.com/our-structure
Verified 2026-04-19 by admin
security_compliance.gdpr_compliant https://openai.com/policies/eu-privacy-policy/
Verified 2026-04-19 by admin
security_compliance.soc2_type2 https://trust.openai.com
Verified 2026-04-19 by admin

Questions to ask before signing

Vendor-agnostic baseline. Send these to the vendor and require written answers before contract.

  1. 01. Provide your most recent SOC 2 Type II report (with bridge letter if applicable).
  2. 02. Describe your training-data provenance and customer opt-out mechanics in writing.
  3. 03. List all sub-processors and confirm notification policy for material additions.
  4. 04. Confirm BAA availability and signed-BAA process if we process PHI.
  5. 05. Describe rate-limiting, quota, and circuit-breaker controls protecting our usage.
  6. 06. Provide your model card or equivalent disclosure documenting intended use, limitations, and known failure modes.
  7. 07. Describe your prompt-injection defences and red-team posture against OWASP LLM Top 10 risks.
  8. 08. Confirm data residency options and which sub-regions our data may touch.
  9. 09. Provide incident-response SLAs, security-event notification timelines, and the most recent pen-test report summary.
  10. 10. Confirm output ownership terms and any indemnification or copyright-shield programs available.
  11. 11. Describe acquisition-risk safeguards and what happens to our data on a change of control.
  12. 12. List foundation-model dependencies and how upstream-model risk is mitigated.

Methodology + caveats

Composite scores use the default-balanced weight profile (25% data handling, 20% IP exposure, 15% jurisdiction, 15% security, 10% regulatory compliance, 8% transparency, 5% business stability, 2% dependency chain). All facts are sourced from the vendor's own public disclosures, public regulatory filings, or reputable secondary reporting — see the cited sources table above. This pack is decision-support material, not legal advice or audit evidence.