English

Places to contact

OpenAI

Type
AI company
Place
United States — USA
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • Coordinated Vulnerability Disclosure Policy · Responsible disclosure programme
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: States: 'We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems.'

    Evidence that this route accepts contact · 2026-09-22

    States: 'We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems.'

    Broad invitation on its face, but the operative programs are on Bugcrowd and split security from safety.

  • OpenAI Bug Bounty (Bugcrowd) · Bug or safety bounty
    Verification expired

    Evidence that this route accepts contact

    Infrastructure/product security. $200 to $20,000.

    URL cited on OpenAI's own policy page; Bugcrowd page is JS-rendered and could not be read directly.

  • OpenAI Safety Bug Bounty (Bugcrowd) · Bug or safety bounty
    Verification expired

    Evidence that this route accepts contact

    Model safety / CBRN jailbreaks. Separate engagement from the main bounty.

    Linked from OpenAI's coordinated disclosure policy. AI Frontiers reports all prompts, completions, findings and communications under it are NDA-covered — you cannot publish what you find.

  • Report Content · Web form
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Publicly open form for policy violations and illegal content: violence and self-harm, sexual exploitation, child exploitation, bullying, fraud, privacy, IP.

    Evidence that this route accepts contact · 2026-09-22

    Publicly open form for policy violations and illegal content: violence and self-harm, sexual exploitation, child exploitation, bullying, fraud, privacy, IP.

    The only genuinely open, no-account-needed public channel. It is a content/abuse route, not an alignment route.

  • Researcher Access Program · Programme or fellowship
    Verification expired · 2026-09-22

    This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.

    Evidence that this route accepts contact · 2026-09-22

    Open and active. Up to $1,000 of API credits for 'researchers using our products to study areas related to the responsible deployment of AI and mitigating associated risks'. Reviewed quarterly.

    Explicitly welcomes 'early stage researchers' and those with 'limited financial and institutional resources'. Low-friction way in.

  • Red Teaming Network · Programme or fellowship
    Verification expired · 2026-09-22

    This route is retained as reference only. Its verification is missing, more than 180 days old, or the contact window is not currently open; do not rely on it until it is re-checked.

    Evidence that this route accepts contact · 2026-09-22

    External domain experts stress-testing models.

    CLOSED. Page states 'Applications are now closed' (deadline was 1 December 2023); says it may reopen. Do not count on it.

  • Model behavior feedback form · Product feedback
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: DEPRECATED. Page now reads: 'We've deprecated this web form in favor of other channels.'

    Evidence that this route accepts contact · 2026-09-22

    DEPRECATED. Page now reads: 'We've deprecated this web form in favor of other channels.'

    Redirects you to in-product thumbs-down, the API dashboard, or support. A named safety channel that was closed.

  • Model Spec feedback form · Product feedback
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: CLOSED. 'This feedback form is now closed.'

    Evidence that this route accepts contact · 2026-09-22

    CLOSED. 'This feedback form is now closed.'

    The public-comment process on the Model Spec no longer exists; updates are now published to a GitHub page instead.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

  • Preparedness Framework v2.0 (15 April 2025); Frontier Governance Framework (May 2026); Model Spec (updated continuously) · Published policy or framework
    Verification expired

    Evidence that this route accepts contact

  • Submission page · Responsible disclosure programme
    Open contact route · 2026-09-22

    Who may use it: public

    Evidence that this route accepts contact · 2026-09-22

    Bugcrowd program: security vulnerabilities in OpenAI's systems and products.

    Security: bugcrowd.com/engagements/openai. Model behaviour: OpenAI now directs ChatGPT users to the thumbs-down control under any response or the content reporting form; API customers to enable thumbs-down feedback in the Playground via the API dashboard; everything else to customer support.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

What it does

Safety Systems, Preparedness and Alignment teams, with a Safety and Security Committee at board level; Preparedness runs capability thresholds and the Model Spec defines intended model behaviour.

Honest assessment

Mixed and worsening for unpaid routes. Two named public feedback channels — the model behavior feedback form and the Model Spec feedback form — are both now closed or deprecated, so a citizen's only open door is the content-report form. OpenAI's September 2026 model misalignment reporting framework is explicitly internal: 'Any OpenAI employee may flag a misalignment example for investigation' — it creates no external intake. Researchers in the Trusted Access for Cyber / Daybreak program publicly complained in August 2026 (TechCrunch, 19 Aug 2026) that access was revoked with messages saying their identity 'could not be verified', disproportionately affecting researchers outside the US and Europe. The Safety Bug Bounty is reported to be NDA-bound, so findings cannot be published.

How to file

Security: bugcrowd.com/engagements/openai. Model behaviour: OpenAI now directs ChatGPT users to the thumbs-down control under any response or the content reporting form; API customers to enable thumbs-down feedback in the Playground via the API dashboard; everything else to customer support.

Format

Security: Bugcrowd vulnerability report. Model behaviour: an in-product thumbs-down with free text — there is no structured external report format any more.

Timing

Rolling.

What happens after

Security reports are triaged and may be rewarded (historically up to $20,000). Model-behaviour feedback disappears into product telemetry with no case number, no acknowledgment and no route back to the reporter.

What it accepts

Bugcrowd program: security vulnerabilities in OpenAI's systems and products.

What it does not accept

The Bugcrowd engagement page states model safety issues, jailbreaks and hallucinations are excluded from the bug bounty and directs them elsewhere. The dedicated 'Model behavior feedback' web form (openai.com/form/model-behavior-feedback) has been deprecated and no longer accepts submissions.

Operated by

OpenAI, security program run on Bugcrowd

Notes

If you have a model-behaviour concern and are not a paid bounty participant, the Report Content form is the only reliable open channel and it is framed around content policy, not alignment. OpenAI's security page says the bug bounty 'provides safe harbor for good-faith testing' but no verbatim safe-harbour clause is published on the policy page itself. No public whistleblower channel for outsiders.

Sources

Something wrong here?