English

Resources · 2 min read

Inbound and outbound disclosure policies are not the same

An outbound policy describes how a company reports flaws it finds elsewhere. It is not evidence that the company accepts reports through that page.

OpenAI’s outbound coordinated-disclosure policy governs vulnerabilities OpenAI discovers in third-party software and reports to those vendors. It does not accept an inbound submission from a member of the public.

To report a vulnerability to OpenAI, use the separately documented inbound security-reporting programme and check its scope. A policy’s direction matters: “we report to others” is not the same as “send your report here.”

Start here →

Who can act on this

Sources

Last checked 2026-09-22