AI Provider Trust Registry evidence verified as of 2026-10-03

Registry / compare

OpenAI API vs Azure OpenAI Service

The same dimension can grade differently depending on who serves the model. Every cell links to its source; grades are evidence grades, not endorsements.

Dimension OpenAI API Azure OpenAI Service
SOC 2 Type II ◐Yes, sales-gated OpenAI’s Trust Portal confirms a SOC 2 Type II report exists but is gated behind a customer login. ◐Yes, sales-gated Microsoft’s official blog states Azure OpenAI meets SOC 2, and SOC 2 reports are only available through the gated Service Trust Portal, so the report exists but is sales‑gated.
ISO 27001 ●Yes, public OpenAI's own public trust portal explicitly states the ISO/IEC 27001:2022 certification covers the API, confirming public evidence. ◔Partial The provider’s official ISO 27001 offering page lists the services covered and excludes Azure OpenAI Service, indicating only partial coverage for this offering.
ISO 42001 ●Yes, public OpenAI’s public security and privacy page explicitly states the ISO/IEC 42001:2023 AI Management System certification, confirming the yes_public claim. ●Yes, public The Microsoft Azure blog publicly states that the ISO/IEC 42001:2023 certification covers Azure OpenAI models, providing verifiable evidence without any access gate.
Trust center ●Yes, public The provider hosts an openly accessible Trust Portal page confirming a maintained compliance portal. ●Yes, public The Microsoft Service Trust Portal publicly hosts an AI Resources page referencing Azure OpenAI, confirming a maintained compliance portal.
HIPAA BAA ◐Yes, sales-gated OpenAI states a BAA for the API is available but must be requested via email, making it sales‑gated. ◐Yes, sales-gated Microsoft states Azure OpenAI is covered by its BAA, but the BAA is only accessible through the gated Service Trust Portal, so the agreement is sales‑gated.
GDPR DPA ●Yes, public OpenAI’s publicly available DPA contains SCC language and references a publicly accessible Sub‑Processor List, confirming the required DPA with SCCs and subprocessor list are... ●Yes, public Microsoft publicly provides the DPA (which includes the EU Model Clauses/SCCs) and also publishes a Subprocessor List linked to that DPA, satisfying both requirements.
No-training default ●Yes, public The OpenAI help article publicly states that by default API data is not used to train models, fulfilling the commitment. ●Yes, public Microsoft’s Azure OpenAI data‑privacy page publicly states that prompts and completions are not used to train foundation models without customer permission, confirming a public...
Retention / ZDR ◐Yes, sales-gated OpenAI documents retention policies and states Zero Data Retention is gated behind sales approval, confirming the yes_sales_gated value. ◔Partial Retention is publicly documented (30 days) and zero-data-retention is only offered after a sales/approval process, so the compound question is only partially satisfied.
Residency ◐Yes, sales-gated OpenAI’s own documentation states data residency is limited to eligible/approved customers, confirming the offering is sales‑gated. ●Yes, public Microsoft docs state that Standard/Regional deployments process data in the specific Azure region of the deployment, allowing region‑level pinning such as to an EU region.
GPAI Code ●Yes, public The EU Commission’s public GPAI Code of Practice signatory list on the referenced page lists OpenAI as a signatory. ●Yes, public The EC GPAI Code of Practice signatory list on the official EU digital strategy page includes OpenAI, confirming the model developer is a public signatory.
Art. 53 summary ●Yes, public OpenAI hosts a publicly accessible PDF titled 'Public Summary of Training Content for GPT-6 Astra' on its own domain, satisfying the Article 53 training‑data summary requirement. -Not applicable The Art. 53 training-content summary is a developer obligation, and per the knowledge base serving-platform rows (e.g. Azure OpenAI Service) are not_applicable, even though...