vulns.co
/
GKData.io MCP

OpenAI · 2 min read

OpenAI Security Bug Bounty

OpenAI · Bugcrowd. Policy reviewed 2026-10-02. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Use only owned or expressly authorized accounts/data; avoid disruption, destruction, social engineering and unrelated third parties. Model-only content issues and intended sandbox behavior generally do not qualify. Disclosure requires permission.

Eligibility and submission status

First qualifying previously unknown issue with meaningful security impact; Bugcrowd account, age-of-majority and payment eligibility requirements apply.

Program displayed active status at review; live terms and eligibility still apply.

Advertised rewards

Advertised maximum $100,000 for exceptional critical findings; category-dependent schedules include amounts from $50. The historical $20,000 ceiling is outdated.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 12 published rows
AssetTypeGroup / eligibility
api.openai.comPublished location: https://api.openai.comapiAPI Targets
ChatGPTPublished location: https://chat.openai.comwebsiteChatGPT
ChatGPT PluginsPublished location: https://chat.openai.comapiChatGPT
Third Party TargetswebsiteThird Party Corporate Targets
OpenAI API KeysapiOpenAI API Keys
https://openai.orgPublished location: https://*.openai.orgwebsiteOpenAI Research Org
*.openai.orgPublished location: https://*.openai.orgapiOpenAI Research Org
openai.comPublished location: https://openai.com/websiteOther OpenAI Targets
*.openai.comotherOther OpenAI Targets
Developer Platform PlaygroundPublished location: https://platform.openai.com/playgroundwebsiteOther OpenAI Targets
OtherotherOther OpenAI Targets
Codex DesktopotherCodex
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Review limitations

  • Live policy was reviewed in a browser because text retrieval omitted its dynamic content.
  • The page displayed active status and an August 19, 2026 update; this is not proof of its full change history.
  • Reward ranges vary by category and remain discretionary; consult the live policy.
  • Currency is displayed as a dollar sign; linked standard terms mention USD generally but program-specific denomination was not explicit. Normalized bounds remain null.

Sources and provenance

  1. OpenAI Security Bug Bounty OpenAI / Bugcrowd · reviewed 2026-10-02
  2. OpenAI program announcements OpenAI / Bugcrowd · reviewed 2026-10-02
  3. Bugcrowd Standard Disclosure Terms Bugcrowd · reviewed 2026-10-02
  4. Published Bugcrowd scope groups OpenAI · reviewed 2026-10-03

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software