← All pages

1. What the document is: A short index page linking OpenAI's security-research policies: a Coordinated Vulnerability Disclosure Policy (bug-bounty/security-research rules), an Outbound Coordinated Disclosure Policy (how OpenAI reports vulnerabilities it finds in *other companies'* software), and (added 2025-11-24) a CVE Assignment Policy (OpenAI's role as a CVE Numbering Authority — the body that assigns official vulnerability ID numbers). Outside this wiki's AI-training/data-licensing focus.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

ChatGPT – Vulnerability Disclosure Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/ChatGPT/Vulnerability Disclosure Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-11-24

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags on this page are LLM-assigned. Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: A short index page linking OpenAI’s security-research policies: a Coordinated Vulnerability Disclosure Policy (bug-bounty/security-research rules), an Outbound Coordinated Disclosure Policy (how OpenAI reports vulnerabilities it finds in other companies’ software), and (added 2025-11-24) a CVE Assignment Policy (OpenAI’s role as a CVE Numbering Authority — the body that assigns official vulnerability ID numbers). Outside this wiki’s AI-training/data-licensing focus.

2. Input rights: Not addressed.

3. Output restrictions: Not addressed.

4. Non-explicit predatory clauses: None found.

5. Regulatory references: None found.

6. Regional variation: Not addressed in this document.

7. Key risk to users: Not applicable — this is a security-research/bug-bounty policy index, not a user-facing data-rights document.

No AI-training, data-licensing, or output-restriction clauses found — out of scope for this wiki’s core risk categories.

Regulatory & Research Context

Davidson et al. (2026) describe “regulatory gray areas” in LLM Terms of Service that create uncertainty for legitimate security research; this index page’s Coordinated Vulnerability Disclosure Policy and CVE Assignment Policy sit adjacent to that concern, structuring how OpenAI defines acceptable security testing rather than addressing AI-training or model-distillation research access. Edwards et al. (2025)‘s “platformisation paradigm” frames such bug-bounty/CVE-authority structures as part of providers’ broader self-governance posture — OpenAI positions itself as the entity that defines and arbitrates “legitimate” security research, paralleling the discretionary control the paradigm associates with neutral-seeming platform intermediaries.


Changes Summary

DateWhat changed
2025-11-11Baseline version (first capture in this dataset; “Updated: June 9, 2025”).
2025-11-24Added a new “CVE assignment policy” section describing OpenAI’s role as a CVE Numbering Authority (CNA) and linking to a new dedicated CVE Assignment Policy document. The two pre-existing policy summaries (Coordinated Vulnerability Disclosure, Outbound Coordinated Disclosure) are unchanged.

Version History

2025-11-11

No AI-training, data-licensing, or output-restriction clauses found in this document.


2025-11-24

No substantive risk change from 2025-11-11 — this date added a new CVE Assignment Policy section, still out of scope for this wiki’s risk categories.