Scaling security with responsible disclosure
OpenAI Blog
OpenAI has introduced an Outbound Coordinated Disclosure Policy to standardize how it reports vulnerabilities it discovers in third-party software. The policy establishes a framework for notifying affected vendors before public disclosure, with timelines and communication protocols designed to give developers time to patch. This approach aims to balance transparency with giving organizations opportunity to address security issues before broader awareness could lead to exploitation.
Why it matters
OpenAI introduces its Outbound Coordinated Disclosure Policy to guide how it responsibly reports vulnerabilities in third-party software—emphasizing integrity, collaboration, and proactive security at scale.