Coordinated vulnerability disclosure policy | OpenAI Skip to main content Research Products Business Developers Company Foundation(opens in a new window) Log in Try ChatGPT (opens in a new window) Research Products Business Developers Company Foundation (opens in a new window) Try ChatGPT (opens in a new window)Login OpenAI Updated: March 25, 2026Coordinated vulnerability disclosure policy Security is essential to OpenAI’s mission. We value the input of hackers acting in good faith to help us maintain a high standard for the security and privacy for our users and technology. This includes encouraging responsible vulnerability research and disclosure. Bug bounty The OpenAI Bug Bounty Program is a way for us to recognize and reward the valuable insights of security researchers who contribute to keeping our technology and company secure. We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems. By sharing your findings, you will play a crucial role in making our technology safer for everyone. Detailed guidelines and rules for participation can be found on our Bug Bounty⁠(opens in a new window) program page, which includes our Safety Bug Bounty⁠(opens in a new window) program. Incident reporting To report a security incident, please let us know immediately⁠ by submitting an encrypted report. Information shared with us in this manner must be shared unconditionally. Outbound coordinated vulnerability disclosure policy OpenAI's framework for responsibly reporting vulnerabilities we discover in third-party software. Rooted in integrity, cooperation, and a commitment to scale, this policy outlines how we work with others to strengthen the broader security ecosystem. Learn more. CVE assignment policy OpenAI’s CVE Assignment Policy explains how we handle vulnerability reports as a CVE Numbering Authority (CNA). CVEs—short for Common Vulnerabilities and Exposures—are standardized identifiers for publicly known software vulnerabilities. This policy describes which types of security issues are in scope, how to submit reports, how CVE identifiers are assigned, and how we coordinate public disclosure. Learn more. Research Research Index Research Overview Economic Research Latest Advancements GPT-5.6 GPT-5.5 GPT-5.4 Safety Safety Approach Deployment Safety (opens in a new window) Security & Privacy Trust & Transparency Products ChatGPT (opens in a new window) ChatGPT Business (opens in a new window) ChatGPT Enterprise (opens in a new window) ChatGPT for Education (opens in a new window) Codex Release Notes API Platform Overview API Log In (opens in a new window) Docs (opens in a new window) Business Overview Solutions Resources Customer Stories Partner Network Contact Sales Developers Apps SDK (opens in a new window) Open Models Docs (opens in a new window) Resources (opens in a new window) Developer Forum (opens in a new window) Company About Us Our Charter Careers News Support Help Center (opens in a new window) More Stories Academy Supply Co. Livestreams Podcast RSS Terms & Policies Terms of Use Privacy Policy Other Policies (opens in a new window) (opens in a new window) (opens in a new window) (opens in a new window) (opens in a new window) (opens in a new window) (opens in a new window) OpenAI © 2015–2026Your privacy choices EnglishUnited States