Data Quality 96/100
01Trust Score

ChatGPT

Conditional Proceed

Week 2026-W22 May 29, 2026 Vendor-Neutral
70 /100 Mostly Positive
→ Unchanged
4.2/5 (5512)
↓ PDF Report
WHY THIS SCORE

The overall trust score of 70 is primarily driven by a strong compliance score of 35/35, reflecting verified SOC 2 Type 2 and ISO 27001 certifications, and the availability of a GDPR DPA. The security/CVE score of 25/25 also contributes positively, indicating robust security measures. However, a significant deduction comes from the legal/IP score of 0/25, largely due to the low liability cap and the 'AS IS' warranty. The market score of 10/15 reflects a generally positive market perception but acknowledges competitive pressures and some community concerns.

ChatGPT presents a mixed risk profile. While enterprise-specific tiers offer robust security and privacy controls, including data training opt-out and regional data residency, other tiers (Free, Go, Plus, Pro, Business) explicitly state that user data may be used for model training, posing significant data leakage and intellectual property risks for corporate use. Legal liabilities are capped at a low amount, and some compliance certifications are claimed but unverified, requiring further due diligence.
Trust Score 70/100 CONDITIONAL
Est. Annual Cost 45500 100 users / yr
Top Risk HIGH Reliability Overall: Medium
Priority Action Prioritize the 'Enterprise' or 'Business ChatGPT & Codex' tiers for all corporate deployments. ↓ PDF  · TCO  · Hardening
Enterprise: DPA: Unknown · Residency: Unknown · Lock-in: Medium (50/100)

Verified Compliance Facts

Cited and timestamped — every claim traceable to an official vendor source.

GDPR
✓ Verified
Source ↗ Checked: May 14, 2026 ✓ Verified
HIPAA
Not yet verified
No citation Checked: May 29, 2026 ⏳ Claimed
ISO/IEC 27001
✓ Verified
Source ↗ Checked: May 29, 2026 ✓ Verified
SOC 2
✓ Verified
Source ↗ Checked: May 29, 2026 ✓ Verified
Sub-processors
  • Microsoft Azure
  • Stripe
  • Twilio
Source ↗ Checked: May 14, 2026 ✓ Verified

Enterprise Verdict

! Conditional Approval
Risk: Medium Confidence: medium 50 sources

Conditional Proceed

ChatGPT offers enterprise-grade features and compliance certifications, making its 'Team' and 'Enterprise' tiers suitable for corporate deployment. However, strict adherence to data governance policies is required, particularly regarding data training opt-out and liability limitations on non-enterprise tiers.
Key Strength

Robust enterprise-grade security features including SAML SSO, MFA, and encryption.

Top Risk

Low liability cap in terms of service poses significant financial exposure.

Priority Action

Prioritize the 'Enterprise' or 'Business ChatGPT & Codex' tiers for all corporate deployments.

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

High Reliability Community Data

Public documentation buyers may want to verify availability of specific uptime commitments or reliability history.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

High Vendor Lock-in Community Data

Data export status unclear. Integration score: 55/100. Webhooks available, reducing lock-in risk.

Low Support Quality Community Data

Average community support/satisfaction rating: 5.0/5.0 based on 1 user reviews.

Medium Data Privacy Community Data

Compliance score: 94/100. GDPR status: dpa_available. Encryption at rest: yes.

Low Compliance Posture Community Data

SOC 2: type_ii. ISO 27001: certified. Overall compliance score: 94/100.

High AI Transparency Verified

Vendor may train on user data. Users retain code/output ownership. Legal/ToS risk score: 40/100.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 202+ community data points

Recommended Inquiry Critical GDPR Fine by Italy's Garante

In December 2024, Italy’s Garante fined OpenAI €15 million for processing EU users’ personal data without sufficient legal basis, transparency, or age verification measures, leading to a temporary ChatGPT ban in Italy. This highlights ongoing regulatory scrutiny and potential compliance risks.

Sources: Web
Recommended Inquiry Medium Inconsistent Application of User Preferences

A Reddit user reported that ChatGPT ignored a stored preference for canonical URLs, despite acknowledging the preference. This suggests a potential consistency bug in ChatGPT's memory/preference system, which could lead to unintended data formatting or exposure.

Sources: Web
Recommended Inquiry High Data Leakage and Retention Issues in Enterprise ChatGPT

Prompts and outputs in ChatGPT Enterprise may contain sensitive data that, if mishandled or retained improperly, could be exposed through logs or integrations. This poses risks of confidential business information loss, PII exposure, and compliance violations.

Sources: Web
03Security & Compliance

Security & Compliance

CAIQ ⏳ Claimed Unverified
CYBER_INSURANCE ⏳ Claimed Unverified
FedRAMP ⏳ Claimed Unverified Pwc
ISO 27001 ~ Active (unverified link) ⚠ Dead link
ISO 27017 ⏳ Claimed Unverified Pwc
ISO 27018 ⏳ Claimed Unverified Pwc
ISO 27701 ⏳ Claimed Unverified Pwc
PCI DSS ⏳ Claimed Unverified Pwc
PEN_TEST ⏳ Claimed Unverified
SOC 2 ~ Claimed Unverified (unverified link) ⚠ Dead link
SOC 3 ⏳ Claimed Unverified Pwc
GDPR ~ DPA (unverified link) ⚠ Dead link
HIPAA Not documented

External Registry Verification

Data Security

Encryption (At Rest): AES-256
Encryption (In Transit): TLS 1.2+

Security Features

SSO
MFA Methods not specified in public documentation
Audit Logs

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

DPA: Unknown Residency: Unknown Lock-in: Medium (50/100)
📄 Data Processing Agreement Unknown
View DPA ↗

OpenAI provides a Data Processing Addendum (DPA) that supplements its Services Agreement, applicable to API, ChatGPT Enterprise, Team, and Edu users. This DPA addresses key GDPR requirements including instructions-only processing, confidentiality, breach notification, and subprocessor vetting.

🌐 Data Residency Unknown

Eligible ChatGPT Enterprise, Edu, and API platform customers can select regional data residency, including options in Europe.

⚠️ Contract Risk Medium Lock-in (50/100)
Notice: 30 days
⚠ 1 contract risk flag — click to review
⚠ Auto-renewal terms and data export rights not publicly documented — verify before signing.

Full contract terms for ChatGPT require direct vendor engagement. Ensure data portability on exit, notice period, and pricing lock clauses are negotiated before execution.

Compliance & Document Matrix

🛡️ Security Certifications

Certification Status Auditor Valid Until Source
CSA CAIQ 📄 Claimed View
Cyber Liability Insurance 📄 Claimed View
FedRAMP Low 📄 Claimed Pwc View
ISO 27001 ✅ Active View
ISO 27017 (Cloud Security) 📄 Claimed Pwc View
ISO 27018 (Cloud Privacy) 📄 Claimed Pwc View
ISO 27701 (Privacy) 📄 Claimed Pwc View
PCI-DSS 📄 Claimed Pwc View
3rd Party Penetration Test 📄 Claimed View
SOC 2 Type II 📄 Claimed View
SOC 3 📄 Claimed Pwc View

🔒 Data Privacy Documents

Document Status URL AI Assessment
Sub-processors ❌ Not Found Link ❌ Not found
AI/Model Training Policy ❌ Not Found Link — Unclear
Data Retention Policy ❌ Not Found Link ❌ Not found
Data Flow Diagram ❌ Not Found
GDPR Compliance Statement ✅ Active Link ❌ Not found
KVKK Compliance Statement ❌ Not Found ❌ Not found
CCPA Compliance Statement ✅ Active Link ❌ Not found

⚖️ Legal Contracts

See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.

🔧 Operational Readiness

Document Status URL AI Assessment
Business Continuity Plan (BCP) ❌ Not Found ❌ Not found
Disaster Recovery Plan (DRP) ❌ Not Found ❌ Not found
Incident Response Plan ❌ Not Found ❌ Not found
3rd Party Penetration Test 📄 Claimed View ❌ Not found

📋 Technical Transparency

Document Status URL AI Assessment
SBOM ❌ Not Found ❌ Not found
OSS License Inventory ❌ Not Found ❌ Not found
Vulnerability Management Policy ✅ Active Link ❌ Not found
Patch Management Policy ❌ Not Found ❌ Not found
Offboarding / Data Export Guide ❌ Not Found ❌ Not found
SIG Questionnaire ❌ Not Found
CAIQ ❌ Not Found

💰 Financial Resilience

Item Status Details
Cyber Liability Insurance 📄 Claimed ion Testing Code Analysis View more ESG ESG Commitment Supplier Code of Conduct Legal Subprocessors Cyber Insurance Dat…
TCO Disclosed ✅ Available Annual: 45500
New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Intelligence

Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.

Intelligence Synthesis

Community discussions on HackerNews and Reddit highlight ChatGPT's widespread adoption and utility for various tasks, from coding to content creation, with users often comparing it favorably to competitors like Claude and Gemini. However, concerns were raised on Reddit regarding inconsistent application of user preferences, and on HackerNews about high token costs for enterprise API usage. Official documentation and web searches confirm robust enterprise security features, including SOC 2 Type 2 certification, GDPR DPA, and data residency options for enterprise tiers, alongside a critical 'no training on your data' policy for these specific plans.

Recurring Issues

Inconsistent Application of Stored User Preferences 🟠 Community 1 mentions medium → Stable

Enterprise Impact: Could lead to operational inefficiencies, non-compliance with internal data handling guidelines (e.g., clean URLs), and user frustration if the AI community feedback suggests room for improvement in consistently adhere to established preferences.

OpenAI should investigate and resolve consistency bugs in its memory/preference system to ensure reliable application of user-defined settings, especially for enterprise users with specific formatting or data requirements.

Sources: Reddit
High Token Burning and Expensive API Calls for Enterprise 🟠 Community 1 mentions medium → Stable

Enterprise Impact: High token costs can significantly increase operational expenses, especially with parallel agents and thousands of engineers, potentially impacting budget predictability and ROI for large-scale AI deployments.

OpenAI should provide more transparent cost management tools and potentially introduce volume discounts or optimized token usage strategies for enterprise clients to mitigate high operational costs.

Sources: HN
AI Hallucinations and Inaccurate Outputs 🟠 Community 1 mentions medium → Stable

Enterprise Impact: Reliance on inaccurate or fabricated outputs can lead to poor decision-making, reputational damage, and compliance risks if misinformation is disseminated internally or externally.

OpenAI should continue to improve model accuracy and provide clear mechanisms for users to report and correct hallucinations. Enterprise users should implement human-in-the-loop verification for critical AI-generated content.

Sources: Web

Source Signals

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Switching Cost Estimate Medium. While data export is undisclosed, the widespread adoption of ChatGPT and its integrations could make switching to a different LLM provider moderately complex, especially for custom GPTs and agent workflows.
Freemium with tiered subscriptions and usage-based options for API/developer-focused plans. Free tier available

Free

Go

Plus

Pro

Business Codex

Business ChatGPT & Codex

Enterprise

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Calculate the real monthly cost for your team. Adjust seats, usage, and pricing tier below.

Estimated Monthly Cost

Base Subscription $0
AI Credits / Tokens $0
Hidden Costs (onboarding, overages, support) $0
Total Monthly TCO $0
Per User / Month $0
Annual Projection $0

Estimated Annual TCO — 100 Users ±20% confidence band

SMB / Pay-as-you-go
$0 – $0 /yr
Midpoint: $0
Assumptions
  • Free tier used as SMB baseline.
Mid-market / Per-seat
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.
Enterprise / Provisioned
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.

Estimates from publicly scraped pricing data.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in