AI Provider Trust Registry evidence verified as of 2026-08-19

Registry / OpenAI API

OpenAI API

developer: OpenAI platform: OpenAI category: first party

OpenAI's first-party API platform for GPT-family models. No training on API business data by default, documented ~30-day abuse-monitoring retention with approval-gated Zero Data Retention, regional data-residency options, and a trust portal (trust.openai.com) covering SOC 2 Type 2 and ISO certifications for the API Platform.

Watch-outs 4

The cells where this offering is not a clean public yes. This is what to check before you sign.

Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
Yes, sales-gated confidence: high · verified 2026-08-19

OpenAI provides a SOC 2 Type II report for its API but it is only downloadable to logged‑in customers via the Trust Portal.

Customers with active trust.openai.com accounts can access the latest report under "Documents."

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
Yes, public confidence: high · verified 2026-08-15

The OpenAI Trust Portal publicly displays the ISO/IEC 27001:2022 certificate and explicitly states it covers the OpenAI API.

OpenAI's ISO/IEC 27001 Certificate is now available at trust.openai.com ... This certificate documents OpenAI's operation an Information Security Management System that conforms to the requirements of ISO/IEC 27001:2022 for OpenAI’s API, ChatGPT Enterprise, and ChatGPT Edu services.

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
Yes, public confidence: high · verified 2026-08-15

The OpenAI security & privacy page publicly states the ISO/IEC 42001 certification, covering its AI products including the API.

OpenAI maintains an ISO/IEC 42001:2023 AI Management System covering OpenAI’s consumer and business AI products and models in its role as an AI producer and AI provider.

source

Trust center Is there a maintained trust center / compliance portal?
Yes, public confidence: high · verified 2026-08-17

OpenAI provides a publicly accessible Trust Portal that includes compliance documentation for the API, confirming a maintained trust center.

The 2025 SOC2 Report for OpenAI's ChatGPT Business Products and API is now available to customers at trust.openai.com

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
Yes, sales-gated confidence: high · verified 2026-08-18

OpenAI provides a BAA for the API only after a gated email request and review, matching the yes_sales_gated definition.

If you require a BAA before you can use our API, email us at [email protected] ... Our team will respond within 1-2 business days. We review each BAA request on a case‑by‑case basis and may need additional information.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
Yes, public confidence: high · verified 2026-08-16

OpenAI provides a publicly accessible Data Processing Addendum that includes SCC‑based transfer provisions and authorizes use of a publicly listed Sub‑Processor List, meeting both requirements.

"it will do so on the basis of agreements containing SCCs that ensure appropriate safeguards for the protection of Customer Data are in place or an adequacy decision issued by the European Commission" and "Customer hereby provides a general authorization to OpenAI to engage the Sub-Processors listed in the Sub-Processor List to process Customer Data in connection with the Services."

source

No-training default Is there a public commitment not to train on customer API data by default?
Yes, public confidence: high · verified 2026-08-15

OpenAI's own Help Center page publicly states that API data is not used for training by default, confirming the commitment.

By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
Yes, sales-gated confidence: high · verified 2026-08-17

OpenAI documents a 30‑day default retention and states Zero Data Retention is only available after sales‑gated approval, matching yes_sales_gated.

By default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days... Eligible customers may have their customer content excluded from these abuse monitoring logs, ... by getting approved for the Zero Data Retention ... Currently, these controls are subject to prior approval by OpenAI and acceptance of additional requirements.

source

Residency Can data be pinned to a region (especially the EU)?
Yes, sales-gated confidence: high · verified 2026-08-15

The OpenAI API data residency feature is documented on OpenAI's own site but is gated: only Enterprise Customers approved for advanced data controls (requires sales contact and prior approval) can use it, making it yes_sales_gated, not publicly self-serve.

Enterprise Customers that have been approved for advanced data controls can enable regional data residency by creating a new Project in the API Platform dashboard and selecting their preferred region.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
Yes, public confidence: high · verified 2026-08-19

The EC's GPAI Code of Practice signatory list publicly includes OpenAI, confirming the developer is on the list.

OpenAI

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
Yes, public confidence: high · verified 2026-08-17

OpenAI’s official EU AI Act help page publicly states it publishes Article 53 training‑data summaries, satisfying the public publication requirement.

In accordance with our obligations under Article 53(1)(d) of the EU AI Act, OpenAI publishes summaries about the content used to train our general-purpose AI models:

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.