メインコンテンツにスキップ
OpenAI

Trusted Access for Cyber の申請

Trusted Access for Cyber は、審査済みの企業顧客およびサイバーセキュリティ専門家が、二重用途のサイバーセキュリティ業務において当社の最先端モデルを利用できるようにします。これらの機能はネットワーク防御者にとって強力な戦力増強手段であると同時に、悪意ある攻撃者が同様のツールを悪用し、攻撃の規模と高度化を図る可能性があることも認識しています。

Trusted Access for Cyber は、メンバーに追加の本人確認と専門的なユースケース情報の提供を義務付けることでこのリスクを軽減します。これらの対策は、すべての潜在的な悪用を防止できるとは期待されていませんが、既存のサイバー保護手段と組み合わせることで、被害のリスクを大幅に軽減し、よりリスクが高く、より影響力の大きい機能を、より広範な防衛コミュニティに提供できるようになります。

参加要件:

  • この申請書を正確に全て記入してください。不正確または不完全な情報は、オンボーディングの遅延または失敗の原因となる可能性があります。
  • アクセス前およびアクセス後に OpenAI から要求された追加情報や説明を提供する意思

お客様/法人の詳細

A. 組織の識別

B. 主な連絡先(提出者)

C. OpenAI との関係

プロフェッショナルユースケース

D. Trusted Access をサイバー分野でどのように活用する予定ですか?

法的条件および証明事項

Trusted Access for Cyber Participant Addendum

These Trusted Access for Cyber Terms (these “Terms”), together with the intake responses and attestations submitted through the intake form at https://openai.com/form/enterprise-trusted-access-for-cyber/ or attached hereto (the “Intake Form” and collectively with the Terms, the “TAC Addendum”), form part of the Services Agreement between OpenAI and the entity named in the Intake Form (“Customer”), and govern Customer’s access to models made available to Customer through the Trusted Access for Cyber (“TAC”) program. "Services Agreement" means the OpenAI Services Agreement available at https://openai.com/policies/services-agreement/⁠ unless and to the extent that (a) Customer and OpenAI have signed an Enterprise Agreement for OpenAI Services, in which case such agreement will govern, or (b) Customer  will access TAC on Amazon Bedrock, in which case the “OpenAI Services Agreement - Amazon Bedrock” available at https://aws.amazon.com/legal/bedrock/third-party-models/(新しいウィンドウで開く) will govern. To participate in TAC, Customer must submit the information in the Intake Form and receive approval from OpenAI. 

  1. Representations and Warranties. Customer represents and warrants that the information in the Intake Form is true and correct in all respects, and Customer will notify OpenAI if there are any material changes to the information submitted in the Intake Form during the term in which TAC is used. Customer acknowledges and agrees that provision of false or misleading information in the Intake Form, or any failure to notify OpenAI in writing if any information provided in the Intake Form has changed or is no longer complete and accurate, will constitute a material breach of the TAC Addendum and the Agreement.

  2. Approved Use Cases. Participation in TAC comes with heightened responsibility. Access to advanced cyber capabilities is granted only for legitimate, defensive, and authorized security purposes (“Approved Use Cases”). Approved Use Cases are intended to enable real-world security testing, vulnerability research, and defensive readiness and do not include uses that may cause harm, disruption, or unauthorized access. Customer is only authorized to use TAC to enable its own personnel to engage in Approved Use Cases and only in compliance with OpenAI’s usage policies at: https://openai.com/policies/usage-policies/⁠, as well as OpenAI’s Cyber Abuse Policy.

  3. Cyber Abuse Policy. We disallow use of our Services to facilitate Cyber Abuse. “Cyber Abuse” means unauthorized access, exploitation, credential theft, data exfiltration, malware or destructive capabilities, social engineering, evasion, lateral movement, denial-of-service activity, or assistance to any sanctioned entities or identified malicious cyber actors.  This does not prohibit benign defensive, educational, research, privacy-protective, incident response, or authorized security testing uses, including malware or vulnerability analysis, responsible disclosure, and red-team planning, so long as the activity does not enable real-world harm, target live systems without authorization or provide actionable assistance for abuse.

  4. Approved Access Credentials. “Approved Access Credentials” are, collectively, the Org ID, API keys, and specific end user IDs approved by OpenAI for any Approved Use Case. Customer may only make TAC access available to its personnel with a valid need to access TAC, and Customer is responsible for all activities that occur using the Approved Access Credentials. Customer may not (a) share or otherwise make the Approved Access Credentials available to third parties, or (b) share or sell access to the capabilities provided under the Approved Access Credentials to third parties without OpenAI’s express prior written consent. Customer must immediately notify OpenAI if it becomes aware of or reasonably suspects unauthorized access or use of Approved Access Credentials, including any use of TAC for a purpose that is not an Approved Use Case.

  5. Additional Actions. OpenAI will have the right to take any action it deems necessary, in its sole discretion, to preserve the safety, security and integrity of the Services or its business, including, without limitation, suspending or terminating Customer’s access to TAC without refund, requiring additional documentation or assurances to permit continued TAC, conditioning TAC use on Customer’s acceptance of additional requirements or limitations, and pursuing all legal and equitable remedies permitted by applicable laws.

  6. Indemnification. Notwithstanding anything to the contrary in the Services Agreement, unless Customer is a government entity prohibited by law from agreeing to this Section, Customer will indemnify, defend, and hold OpenAI and its affiliates harmless against any liabilities, damages, and costs (including reasonable attorneys’ fees) payable to a third party arising out of any use of the Approved Access Credentials in violation of this TAC Addendum. Limitations on Customer’s liability in the Services Agreement do not apply to this TAC Addendum.

If OpenAI approves you for Government Trusted Access for Cyber ("GTAC"), the following additional terms apply.

  1. GTAC access is intended only for approved users performing lawful, authorized defensive cybersecurity work supporting an approved government mission, government environment, or government-validated protected infrastructure. 

  2. Consistent with the OpenAI Usage Policies, GTAC may not be used for offensive operations, gaining unauthorized access, malware deployment or improvement, credential theft, phishing, data exfiltration, sabotage, or denial-of-service activity.

  3. GTAC is not available for general corporate security, commercial product development, resale, proxying, embedding, customer-facing product traffic, downstream third-party use, or other work outside the approved GTAC scope. Contractors, defense industrial base companies, integrators, cybersecurity vendors, and other non-government entities may use GTAC only to support the approved GTAC scope.


  1. 私は申請書を確認し、提供された情報が、十分な調査と合理的な注意を払った上で、私の知る限りにおいて正確かつ完全であることを表明し、確認します。

  2. 私はお客様を代理して本書類に署名する権限を有しており、TACを推進するために必要なすべての社内承認を取得済みです。

  3. 本申請書に記載された情報が正確で完全でない、または正確で完全でなくなったことを知った場合、直ちに書面で OpenAI に通知します。

  4. お客様は、本申請書に記載されている法的条件に同意し、これらの条件はサービス利用規約に組み込まれます。


注:送信後、本人確認のための簡単な確認手続きを行っていただきます。これには、政府発行の身分証明書の確認と、事業に関する基本情報の提供が含まれます。