1. What the document is: A short index page linking OpenAI's security-research policies: a Coordinated Vulnerability Disclosure Policy (bug-bounty/security-research rules), an Outbound Coordinated Disclosure Policy (how OpenAI reports vulnerabilities it finds in *other companies'* software), and (added 2025-11-24) a CVE Assignment Policy (OpenAI's role as a CVE Numbering Authority — the body that assigns official vulnerability ID numbers). Outside this wiki's AI-training/data-licensing focus.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
ChatGPT – Vulnerability Disclosure Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/ChatGPT/Vulnerability Disclosure Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2025-11-24
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: A short index page linking OpenAI’s security-research policies: a Coordinated Vulnerability Disclosure Policy (bug-bounty/security-research rules), an Outbound Coordinated Disclosure Policy (how OpenAI reports vulnerabilities it finds in other companies’ software), and (added 2025-11-24) a CVE Assignment Policy (OpenAI’s role as a CVE Numbering Authority — the body that assigns official vulnerability ID numbers). Outside this wiki’s AI-training/data-licensing focus.
2. Input rights: Not addressed.
3. Output restrictions: Not addressed.
4. Non-explicit predatory clauses: None found.
5. Regulatory references: None found.
6. Regional variation: Not addressed in this document.
7. Key risk to users: Not applicable — this is a security-research/bug-bounty policy index, not a user-facing data-rights document.
No AI-training, data-licensing, or output-restriction clauses found — out of scope for this wiki’s core risk categories.
Regulatory & Research Context
Davidson et al. (2026) describe “regulatory gray areas” in LLM Terms of Service that create uncertainty for legitimate security research; this index page’s Coordinated Vulnerability Disclosure Policy and CVE Assignment Policy sit adjacent to that concern, structuring how OpenAI defines acceptable security testing rather than addressing AI-training or model-distillation research access. Edwards et al. (2025)‘s “platformisation paradigm” frames such bug-bounty/CVE-authority structures as part of providers’ broader self-governance posture — OpenAI positions itself as the entity that defines and arbitrates “legitimate” security research, paralleling the discretionary control the paradigm associates with neutral-seeming platform intermediaries.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline version (first capture in this dataset; “Updated: June 9, 2025”). |
| 2025-11-24 | Added a new “CVE assignment policy” section describing OpenAI’s role as a CVE Numbering Authority (CNA) and linking to a new dedicated CVE Assignment Policy document. The two pre-existing policy summaries (Coordinated Vulnerability Disclosure, Outbound Coordinated Disclosure) are unchanged. |
Version History
2025-11-11
- Explicit AI clause: NO
- Non-explicit predatory: NO
- Flagged keywords: (none)
No AI-training, data-licensing, or output-restriction clauses found in this document.
2025-11-24
- Explicit AI clause: NO
- Non-explicit predatory: NO
- Flagged keywords: (none)
No substantive risk change from 2025-11-11 — this date added a new CVE Assignment Policy section, still out of scope for this wiki’s risk categories.