ChatGPT
Enterprise-Ready
This vendor is rated as Enterprise-Ready with a score of 79 out of 100. Key strengths include confirmed SOC 2 and ISO 27001 certifications, with audit reports available under NDA. However, a material security finding is CVE-2025-43714 (MEDIUM) with no fix listed, and a new sub-processor has been added, meaning a new third party may now process your data. The buyer should request a Data Processing Agreement (DPA) and confirm the remediation timeline for CVE-2025-43714.
Readiness Breakdown deterministic · evidence-only
- Independent Certification SOC 2 / ISO certifications confirmed via the vendor's trust portal (ISO 27001). Audit report available under NDA — standard enterprise practice.
- Vendor-Stated Compliance Vendor states (cited, not independently audited): BAA Available (HIPAA), GDPR, HIPAA, ISO 27001, SOC 2.
- Customer-Data Training Enterprise terms: does NOT train on customer data (consumer/free tiers may differ — see breakdown).
- Data Processing Agreement No public DPA located — request one during procurement.
- Breach History No known breaches in Have I Been Pwned.
- Vulnerability Exposure 1 known CVE(s); none currently in CISA KEV.
- Email Spoofing Protection (DMARC) DMARC enforced — domain spoofing mitigated.
- Vulnerability Disclosure Policy Publishes a security.txt disclosure policy (RFC 9116).
- Web TLS Certificate Valid TLS certificate in place.
- Legal Transparency 4 legal/policy documents publicly tracked.
Ask This in Your Security Review 1 open items
- Data Processing AgreementRequest the Data Processing Agreement (DPA) and current sub-processor list.
Compliance Posture vendor-stated · cited
| Framework | Status | Source |
|---|---|---|
| GDPR | Stated by vendor | https://openai.com/policies/eu-privacy-policy/ |
| ISO 27001 | Stated by vendor | https://trust.openai.com/ |
| SOC 2 | Stated by vendor | https://trust.openai.com/ |
| HIPAA | Not publicly verified | — |
| BAA Available (HIPAA) | Not publicly verified | — |
Data & Contract Facts deterministic · cited
| Attribute | Value | Source |
|---|---|---|
| Sub-processors (published list) | View document → | https://openai.com/policies/subprocessors |
| Trains on Customer Data key clause |
Free / Pro:
trains on data
ChatGPT Free/Plus: conversations may be used to train models unless you turn off 'Improve the model for everyone' in Data Controls.
cited →
Enterprise:
does not train
ChatGPT Business/Enterprise/Edu and the API: business data (inputs and outputs) is excluded from model training by default; training only occurs if the customer explicitly opts in.
cited →
|
see per-tier citations |
Security Posture authoritative · cited
Security & Compliance Timeline authoritative · dated
- 2025-05-19 CVE CVE-2025-43714 disclosed (MEDIUM · no fix listed)
Certifications Available Under NDA / Trust Center attested · report gated
| Certification | Status | Trust Center |
|---|---|---|
| ISO 27001 | Available via Trust Center | https://trust.openai.com |
Vendor-Claimed, Not Independently Verified treat as unconfirmed
| CAIQ | claimed_unverified | https://trust.openai.com |
| CYBER INSURANCE | claimed_unverified | https://trust.openai.com |
| FEDRAMP LOW | claimed_unverified | https://trust.openai.com |
| ISO 27017 | claimed_unverified | https://trust.openai.com |
| ISO 27018 | claimed_unverified | https://trust.openai.com |
| ISO 27701 | claimed_unverified | https://trust.openai.com |
| PCI DSS | claimed_unverified | https://trust.openai.com |
| PEN TEST | claimed_unverified | https://trust.openai.com |
| SOC2 TYPE2 | claimed_unverified | https://trust.openai.com |
| SOC3 | claimed_unverified | https://trust.openai.com |
Tracked Legal & Policy Documents
| Document | URL |
|---|---|
| Ccpa Compliance | https://openai.com/policies/privacy-policy |
| Gdpr Compliance | https://openai.com/policies/data-processing-addendum |
| Trust | https://trust.openai.com/ |
| Vuln Mgmt | https://openai.com/.well-known/security.txt |
How to Obtain Non-Public Documents
These documents were not found at a public URL — which is normal. Many are provided on request, only on enterprise plans, or via the vendor's trust portal. Here is where each lives and what to do to get it.
| Document | Availability | How to obtain |
|---|---|---|
| Data Processing Addendum (DPA) | On request / trust portal | No public DPA link was found. Most vendors provide a DPA on request or let you accept one through their trust/legal portal. Start at the trust center, or email the vendor's privacy team (commonly privacy@<vendor-domain>). Trust center → |
| Sub-processor List | Trust portal / on request | A public sub-processor list was not found. Many vendors publish it behind a trust-portal login or send it on request. Request access through the trust center or from the vendor's privacy/security team. Trust center → |
| Business Associate Agreement (BAA) | On request | OpenAI will sign a BAA for ChatGPT Enterprise and the API where PHI is processed. Request one by emailing baa@openai.com. Trust center → |
| Master Services Agreement (MSA) | Negotiated per contract | The MSA governs enterprise contracts and is negotiated per deal, so there is usually no public link. Self-serve plans are covered by the public Terms of Service instead; for an MSA, ask the vendor's sales team during procurement. Trust center → |
| Service Level Agreement (SLA) | Enterprise tier | A formal uptime/support SLA is generally offered only on enterprise/paid plans and attached to the order form. Ask sales for the SLA exhibit or check the enterprise pricing page; the trust center often summarises uptime commitments. Trust center → |
Continuous Monitoring change-tracking active
1 legal & policy document under change-monitoring since 2026-05-31. 3 tracked changes detected since baseline.
| Detected | Change | Detail |
|---|---|---|
| 2026-06-15 | Sub-processor Change |
1 new sub-processor(s) added: https://openai.com/policies/subprocessors.
What this means: A new third party may now process your data — check it against your DPA's approved sub-processor list and your notification rights.
|
| 2026-06-08 | Governance Readiness Change |
Governance readiness downgraded: Enterprise-Ready → Conditional. Driven by: 1 new CVE (published from 2025-05-19): CVE-2025-43714. 1 of these have no vendor fix
What this means: This vendor's overall governance posture dropped a tier, driven by 1 change this period (see the summary below) — re-check whether it still meets your bar before renewal or expansion.
|
| 2026-06-08 | CVE / Security Incident |
1 new CVE (published from 2025-05-19): CVE-2025-43714. 1 of these have no vendor fix listed yet (CVE-2025-43714).
What this means: A newly disclosed vulnerability has no vendor fix listed yet — ask for the remediation timeline and confirm your exposure.
|
Ask the Legal Documents grounded · cited
Ask a question about ChatGPT's captured Terms, DPA, Privacy Policy or sub-processor list. Answers are read only from the actual document text and always shown with the exact clause. If the documents don't cover it, we say so — we never guess.
The summary only restates the clauses below it and is verified against them — the verbatim clause is always the source of truth.
Monitor ChatGPT — get alerted when this changes
This brief is a point-in-time snapshot. Vendors quietly revise their DPA, sub-processors, certifications and security posture — and disclose new CVEs. Get a priority email the moment ChatGPT changes something that affects your risk. Built for procurement & security teams.