Inbound and outbound disclosure policies are not the same
An outbound policy describes how a company reports flaws it finds elsewhere. It is not evidence that the company accepts reports through that page.
OpenAI’s outbound coordinated-disclosure policy governs vulnerabilities OpenAI discovers in third-party software and reports to those vendors. It does not accept an inbound submission from a member of the public.
To report a vulnerability to OpenAI, use the separately documented inbound security-reporting programme and check its scope. A policy’s direction matters: “we report to others” is not the same as “send your report here.”