Loading the catalogue…
Loading the catalogue…
Compliance posture
Sovereignty ladder · how the level was reached
Stav's assessment · serving-side
OpenAI serves inference as a US-incorporated operator (OpenAI, L.L.C., with OpenAI Ireland Ltd as the EEA legal counterparty), and is fully within CLOUD Act and US civil-discovery reach — a 2025 federal preservation order in NYT litigation forced retention of deleted chat logs and overrode OpenAI's own 30-day deletion promise for all but Enterprise/ZDR customers, and a documented DHS warrant compelled disclosure of a specific user's prompts. EU/regional data residency exists but is an opt-in, sales-gated feature on new projects rather than the default posture, so the composite is pulled down heavily by weak legal_exposure and serving_residency scores despite a genuinely strong security_posture (SOC 2 II, ISO 27001-family, ISO 42001) and a reasonably solid contractual_posture (published DPA, SCCs, transparency reporting). The weakest link is legal_exposure — the preservation-order precedent shows privacy commitments are subordinate to US court process for the default (non-Enterprise, non-ZDR) serving path. Given this, Stav's operational verdict is routed-only: EU-region residency and ZDR/Enterprise contracts can materially improve the posture for specific workloads, but the default global serving path does not qualify as sovereign EEA serving and requires a documented derogation or enterprise-grade contractual carve-out before regulated EU data is sent.
The default global endpoint (api.openai.com) and default ChatGPT tiers process data outside the EU; EU in-region processing via eu.api.openai.com requires sales-gated approval, cannot be retrofitted to existing projects, and even then extended prompt caching can temporarily leave the region.
Certifications & legal documents
Endpoints served · 91
OpenAI (US, L.L.C.) is a US-incorporated operator squarely subject to CLOUD Act/FISA/subpoena reach — demonstrated by a documented 2025 DHS warrant compelling disclosure of a user's prompts and a federal court preservation order that overrode OpenAI's own 30-day deletion policy for all non-Enterprise/non-ZDR customers.
Default API retention is up to 30 days and ChatGPT non-business tiers train/retain by default; Zero Data Retention is available but only on eligible endpoints/approved customers, and the 2025 litigation hold proved that even the deletion commitment can be legally suspended for non-ZDR/non-Enterprise traffic.
OpenAI holds a broad, currently-sourced certification set (SOC 2 Type II, ISO 27001/27017/27018/27701, ISO 42001) with a public bug-bounty and remediation program, offset by a documented 2023 Redis-bug breach exposing chat titles and some billing data.
A published DPA, SCC-governed sub-processor list, and biannual government-request transparency reports are in place, with a distinct EEA counterparty (OpenAI Ireland Ltd) for EU/UK users, though the multi-cloud (Azure/AWS/GCP/Oracle/CoreWeave) sub-processor footprint is expanding the contractual surface to track.
Risk assessment
A May 2025 federal court preservation order in the NYT copyright litigation compelled OpenAI to retain all ChatGPT output logs indefinitely, including chats users had deleted, overriding OpenAI's own 30-day deletion policy; only Enterprise and Zero Data Retention (ZDR) API customers were excluded. The order was lifted in October 2025 but logs already preserved remain accessible and account-specific holds persist. source ↗
LEGAL_EXPOSUREAs a US-headquartered operator, OpenAI (via OpenAI US) is subject to US legal process (subpoena, warrant, FISA/National Security Letters) that can compel disclosure of customer data regardless of where it is physically hosted; a documented DHS warrant in 2025 compelled disclosure of a specific user's ChatGPT prompts. source ↗
LEGAL_EXPOSUREThe default API endpoint (api.openai.com) and default ChatGPT tiers process data outside the EU by default; EU-region processing via eu.api.openai.com or EU ChatGPT Enterprise/Edu workspaces requires the customer to be approved for 'advanced data controls' and to explicitly configure a new project — existing projects cannot be retrofitted. source ↗
DATA_RESIDENCYOpenAI's default API retention keeps inputs/outputs for up to 30 days for abuse-monitoring purposes unless the customer is separately approved for Zero Data Retention (ZDR) on eligible endpoints; not all endpoints (e.g. some Realtime/tracing features) are ZDR-eligible. source ↗
SERVING_RETENTIONOpenAI's serving infrastructure now spans multiple hyperscalers and GPU cloud vendors beyond its original Azure-exclusive arrangement, including a new seven-year AWS compute partnership alongside existing Google Cloud, Oracle and CoreWeave relationships, broadening the jurisdictional and vendor-risk surface behind the 'OpenAI' brand. source ↗
SUBPROCESSINGIn March 2023, a bug in the Redis open-source library caused a data breach exposing other users' chat titles and, for roughly 1.2% of active ChatGPT Plus subscribers, billing-related information (name, billing address, card type, expiry, last 4 digits). source ↗
SECURITYEven within EU-residency-configured projects, extended prompt caching in regions that do not support regional processing may require OpenAI to temporarily process and store Customer Content outside the selected region. source ↗
DATA_RESIDENCYThird-party outage trackers report a high frequency of minor service incidents (on the order of 100+ per year) affecting ChatGPT/API components, though most are resolved within roughly 1-2 hours according to aggregated monitoring. source ↗
RESILIENCEOpenAI serves customers through distinct legal entities depending on region (OpenAI US for US/rest-of-world users, OpenAI Ireland Ltd for EEA/UK users under Irish/EU law), which customers must correctly identify for notice, liability and law-enforcement-request purposes. source ↗
GOVERNANCESafeguards
OpenAI offers customer-selectable regional data residency (storage and, for eligible endpoints via eu.api.openai.com, in-region processing with TLS termination in-region) for Europe, UK, US, Canada, Japan, South Korea, Singapore, India, Australia and UAE, for eligible API, ChatGPT Enterprise and ChatGPT Edu customers. source ↗
By default, OpenAI does not train on inputs or outputs from business products (ChatGPT Business, ChatGPT Enterprise, and the API); organizations must explicitly opt in to allow data sharing for model improvement. source ↗
Zero Data Retention (ZDR) is available for eligible API endpoints/customers, meaning prompts and outputs are not stored after the request completes, and such data was explicitly exempted from the 2025 litigation preservation order. source ↗
OpenAI publishes a Data Processing Addendum covering GDPR roles/responsibilities and uses Standard Contractual Clauses as the transfer mechanism among its own affiliates and sub-processors. source ↗
OpenAI publishes recurring biannual 'Report on Government Requests for User Data' transparency reports and a public Law Enforcement Policy detailing legal-process requirements (subpoena/warrant) and emergency-disclosure criteria. source ↗
OpenAI maintains SOC 2 Type II, ISO/IEC 27001, 27017, 27018, 27701, and 42001, PCI DSS v4.0.1, and CSA STAR attestations, published via its Trust Portal. source ↗
Following the 2023 Redis breach, OpenAI implemented remediation (redundant cross-user checks, log auditing) and launched a public bug bounty program with rewards up to $20,000 for critical findings. source ↗
Privacy-policy issues
Court process can override stated retention/deletion policy source ↗
A 2025 US federal litigation preservation order forced OpenAI to retain deleted/temporary ChatGPT chats indefinitely for non-Enterprise, non-ZDR customers, showing that the published 30-day deletion promise is subordinate to US civil discovery obligations.
EU/regional residency is opt-in and sales-gated, not default source ↗
Customers must apply for and be approved for 'advanced data controls' and create a new project on eu.api.openai.com to get in-region processing; the default global endpoint does not guarantee EU processing.
Ambiguity in extended prompt caching data flows source ↗
OpenAI's own documentation notes that extended prompt caching in regions without regional-processing support may temporarily store customer content outside the configured residency region.