Skip to main content
TrustEdge AI
Model developer

OpenAI

Frontier model developer. GPT models via the first-party API Platform, plus ChatGPT Business, Enterprise, Edu and Healthcare workspaces.

7 of 7 criteria carry a sourced value ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not OpenAI’s. Every statement here traces to a sourced claim further down the page.

The broadest certification portfolio of any developer here, with a BAA available on request and a retention story that is clear but conditional.

Where it is strong

  • Certification breadth is the widest of the developers tracked: SOC 2 Type 2, SOC 3, four ISO 27000-family standards, ISO/IEC 42001:2023, CSA STAR, FedRAMP 20x, TX-RAMP and PCI DSS.
  • Business data is excluded from training by default across the API Platform and every ChatGPT business tier.
  • Retention is a published number — 30 days — rather than an open-ended purpose test.
  • Sub-processor list carries product, processing location and purpose per entity, which is more granular than a bare name list.

What to check or negotiate

  • The BAA is phrased as a capability exercised on request — "we are able to sign" — with no feature-level exclusions published. Absence of published exclusions is not the same as absence of exclusions; get the scope in the executed agreement.
  • Zero data retention is conditional on both endpoint eligibility and a "qualifying use-case", so it is not a switch a customer can simply turn on.
  • ISO 27001 is scoped to the API, ChatGPT Enterprise and ChatGPT Edu — narrower than the full product surface.
  • ISO/IEC 42001:2023 appears in the trust portal badge list but not in the prose sentence enumerating certifications. Ask for the certificate and its scope.
  • Sub-processor notification is opt-in and carries no committed advance-notice period.

Verdict

A strong default for regulated work provided you obtain the BAA in writing and confirm which endpoints your workload actually touches.

The full record

Every criterion, with OpenAI’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

C · 2.28 (Summer 2026)

Second overall of the nine companies graded. Shared the highest Existential Safety grade awarded to anyone in the Index, a D+.

Primary source · verified 2026-08-07

BAA available

Will they sign a business associate agreement for PHI

Yes

OpenAI: "We are able to sign Business Associate Agreements (BAA) in support of customers’ compliance with the Health Insurance Portability and Accountability Act (HIPAA). Please reach out if you require a BAA." Phrased as a capability exercised on request rather than a standing term, and this page states no feature-level exclusions — unlike Anthropic, which enumerates them. Confirm scope in the executed agreement. ChatGPT for Healthcare is described separately as "a secure workspace designed to support HIPAA compliance".

Primary source · verified 2026-08-05

Certifications

Independently audited attestations

SOC 2 Type 2 · SOC 3 · ISO/IEC 27001:2022 · ISO/IEC 27017:2015 · ISO/IEC 27018:2019 · ISO/IEC 27701:2019 · ISO/IEC 42001:2023 · CSA STAR · FedRAMP 20x · TX-RAMP · PCI DSS v4.0.1

Taken from the Compliance section of OpenAI’s Trust Portal. Note a mismatch worth carrying into diligence: the portal’s prose says only that "Our products are also ISO 27001, 27017, 27018, and 27701 certified" — ISO/IEC 42001:2023, the AI management system standard, appears in the badge list but not in that sentence. The ISO 27001 certificate is scoped "for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services", so certification scope is narrower than the product surface.

Primary source · verified 2026-08-07

Trains on your data

Whether your inputs and outputs feed model training

Not by default — Opt-in. Business data is excluded by default across the API Platform and the ChatGPT business tiers; explicitly opting in, including via feedback mechanisms, permits training use.

OpenAI: "By default, we do not use your business data for training our models. If you have explicitly opted in to share your data with us (for example, through our opt-in feedback mechanisms) to improve our services, then we may use the shared data to train our models." The exclusion is dated: it covers API Platform data "(after March 1, 2023)".

Primary source · verified 2026-08-05

Retention

How long your data is kept, and where

API inputs and outputs retained up to 30 days for abuse detection; zero data retention available for eligible endpoints on approval.

OpenAI: "Except for certain endpoints and features listed in our platform documentation, OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. You can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case." ZDR is conditional on both endpoint eligibility and a "qualifying use-case", so it is not a setting a customer can simply switch on. Fine-tuning data is retained "until the customer deletes the files".

Primary source · verified 2026-08-05

Subprocessors

Who else processes your data

Named list of roughly 25 third-party sub-processors with product, processing location and purpose; opt-in email notification of additions.

Last updated by OpenAI on June 2, 2026. Columns are Entity Name, OpenAI Product or Service, Location of Processing and Purpose of Processing, which is more granular than a bare name list. Notification is opt-in and un-timed: "Sign up to receive notification of new third party Subprocessors by filling out this form." No advance-notice period is committed to, in contrast to AWS (30 days) and Microsoft (six months).

Primary source · verified 2026-07-08

EU AI Act

Obligations, and which transfer to you as deployer

Signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

Read from the European Commission’s published signatory list rather than from OpenAI’s own announcement.

Primary source · verified 2026-08-07

This is a model developer, so the FLI grade above describes its safety-research posture. It says nothing about whether a deployment is compliant — that comes from the contractual terms, either this vendor’s own or those of a platform you run the model through.

This developer’s models are also available through Azure OpenAI (Microsoft Foundry), under those platforms’ terms rather than these. Where the direct API cannot meet a requirement, the platform route often can.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying OpenAI in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.