SaaSDossier

No. 003 · Public Edition · Free sample

OpenAI — Security Evidence Dossier

Question
What security evidence does OpenAI publish?
Answer
OpenAI publishes a public trust portal and security documentation: SOC 2 Type II, encryption in transit and at rest, access controls and single sign-on, data-retention and privacy commitments, subprocessor information, and enterprise data-handling terms. Of 55 fields, 47 are Documented and 8 are Questions surfaced for buyer follow-up. This is the free Public Edition.
47 Documented8 Questions surfacedof 55
Cover of the OpenAI Security Evidence Dossier — Public Edition, Dossier No. 003
Edition
Public Edition
Reference
Dossier No. 003
Framework
55 fields · 10 domains
Documented
47 of 55
Questions surfaced
8
Evidence date
22 June 2026
Vendor pages reviewed
14
Price
Free — Public Edition
Reviewer
A. Vale · SD-R01

10 domains reviewed

  • Identity & legal entity
  • Standards & attestations
  • Privacy & compliance
  • Encryption & key management
  • Infrastructure & hosting
  • Access control
  • Vulnerability & incident response
  • Subprocessors & supply chain
  • AI governance
  • Secure development & organization

What's inside

Evidence ledger

All 55 fields across 10 domains, each recorded in one of two states, with the vendor's own words quoted and cited where Documented.

Source register

Every vendor-published page reviewed, listed with its URL, so each line traces back to where it was found.

Integrity record

A SHA-256 record so the released document can be confirmed unchanged.

Vendor question pack

The Questions surfaced, gathered as ready-to-send follow-ups for your procurement or security conversation.

Question surfaced means: Not identified in the vendor-published sources reviewed. This does not establish absence of the control.