메인 콘텐츠로 건너뛰기
OpenAI

OpenAI 파일럿 요청: Trusted Access For Cyber

Trusted Access for Cyber는 검증된 기업 고객과 사이버 보안 실무자가 이중 용도의 사이버 보안 작업을 위해 당사의 가장 강력한 모델을 사용할 수 있도록 합니다. OpenAI는 이러한 기능을 네트워크 방어자의 역량을 크게 강화하는 수단으로 보면서도, 악의적인 행위자가 동일한 툴을 악용하여 공격의 규모와 정교함을 높이려 할 수 있음을 인식하고 있습니다.

Trusted Access for Cyber는 회원에게 추가 신원 정보와 전문 사용 사례 정보를 제공하도록 요구함으로써 이러한 위험을 완화합니다. 이러한 조치만으로 모든 잠재적 오남용을 완전히 막을 수는 없지만, 이는 기존의 사이버 보호 체계와 함께 작동하여 피해 위험을 실질적으로 낮추고, 더 높은 위험과 더 큰 영향을 수반하는 기능을 보다 폭넓은 방어자 커뮤니티에 제공할 수 있도록 합니다.

참여 요건:

  • 본 신청서를 전체적으로 정확하게 작성해야 하며, 부정확하거나 불완전한 정보는 온보딩 지연 또는 실패로 이어질 수 있습니다.
  • 액세스 전후에 OpenAI가 요청하는 추가 정보 또는 설명을 제공할 의지가 있어야 합니다.

고객/엔티티 세부 정보

A. 조직 식별 정보

B. 주요 연락 담당자(제출자)

C. OpenAI와의 관계

전문적인 사용 사례

D. Trusted Access for Cyber를 어떻게 활용할 계획인가요?

법률 약관 및 확인 진술

Trusted Access for Cyber Participant Addendum

These Trusted Access for Cyber Terms (these “Terms”), together with the intake responses and attestations submitted through the intake form at https://openai.com/form/enterprise-trusted-access-for-cyber/ or attached hereto (the “Intake Form” and collectively with the Terms, the “TAC Addendum”), form part of the Services Agreement between OpenAI and the entity named in the Intake Form (“Customer”), and govern Customer’s access to models made available to Customer through the Trusted Access for Cyber (“TAC”) program. "Services Agreement" means the OpenAI Services Agreement available at https://openai.com/policies/services-agreement/⁠ unless and to the extent that (a) Customer and OpenAI have signed an Enterprise Agreement for OpenAI Services, in which case such agreement will govern, or (b) Customer  will access TAC on Amazon Bedrock, in which case the “OpenAI Services Agreement - Amazon Bedrock” available at https://aws.amazon.com/legal/bedrock/third-party-models/(새 창에서 열기) will govern. To participate in TAC, Customer must submit the information in the Intake Form and receive approval from OpenAI. 

  1. Representations and Warranties. Customer represents and warrants that the information in the Intake Form is true and correct in all respects, and Customer will notify OpenAI if there are any material changes to the information submitted in the Intake Form during the term in which TAC is used. Customer acknowledges and agrees that provision of false or misleading information in the Intake Form, or any failure to notify OpenAI in writing if any information provided in the Intake Form has changed or is no longer complete and accurate, will constitute a material breach of the TAC Addendum and the Agreement.

  2. Approved Use Cases. Participation in TAC comes with heightened responsibility. Access to advanced cyber capabilities is granted only for legitimate, defensive, and authorized security purposes (“Approved Use Cases”). Approved Use Cases are intended to enable real-world security testing, vulnerability research, and defensive readiness and do not include uses that may cause harm, disruption, or unauthorized access. Customer is only authorized to use TAC to enable its own personnel to engage in Approved Use Cases and only in compliance with OpenAI’s usage policies at: https://openai.com/policies/usage-policies/⁠, as well as OpenAI’s Cyber Abuse Policy.

  3. Cyber Abuse Policy. We disallow use of our Services to facilitate Cyber Abuse. “Cyber Abuse” means unauthorized access, exploitation, credential theft, data exfiltration, malware or destructive capabilities, social engineering, evasion, lateral movement, denial-of-service activity, or assistance to any sanctioned entities or identified malicious cyber actors.  This does not prohibit benign defensive, educational, research, privacy-protective, incident response, or authorized security testing uses, including malware or vulnerability analysis, responsible disclosure, and red-team planning, so long as the activity does not enable real-world harm, target live systems without authorization or provide actionable assistance for abuse.

  4. Approved Access Credentials. “Approved Access Credentials” are, collectively, the Org ID, API keys, and specific end user IDs approved by OpenAI for any Approved Use Case. Customer may only make TAC access available to its personnel with a valid need to access TAC, and Customer is responsible for all activities that occur using the Approved Access Credentials. Customer may not (a) share or otherwise make the Approved Access Credentials available to third parties, or (b) share or sell access to the capabilities provided under the Approved Access Credentials to third parties without OpenAI’s express prior written consent. Customer must immediately notify OpenAI if it becomes aware of or reasonably suspects unauthorized access or use of Approved Access Credentials, including any use of TAC for a purpose that is not an Approved Use Case.

  5. Additional Actions. OpenAI will have the right to take any action it deems necessary, in its sole discretion, to preserve the safety, security and integrity of the Services or its business, including, without limitation, suspending or terminating Customer’s access to TAC without refund, requiring additional documentation or assurances to permit continued TAC, conditioning TAC use on Customer’s acceptance of additional requirements or limitations, and pursuing all legal and equitable remedies permitted by applicable laws.

  6. Indemnification. Notwithstanding anything to the contrary in the Services Agreement, unless Customer is a government entity prohibited by law from agreeing to this Section, Customer will indemnify, defend, and hold OpenAI and its affiliates harmless against any liabilities, damages, and costs (including reasonable attorneys’ fees) payable to a third party arising out of any use of the Approved Access Credentials in violation of this TAC Addendum. Limitations on Customer’s liability in the Services Agreement do not apply to this TAC Addendum.

If OpenAI approves you for Government Trusted Access for Cyber ("GTAC"), the following additional terms apply.

  1. GTAC access is intended only for approved users performing lawful, authorized defensive cybersecurity work supporting an approved government mission, government environment, or government-validated protected infrastructure. 

  2. Consistent with the OpenAI Usage Policies, GTAC may not be used for offensive operations, gaining unauthorized access, malware deployment or improvement, credential theft, phishing, data exfiltration, sabotage, or denial-of-service activity.

  3. GTAC is not available for general corporate security, commercial product development, resale, proxying, embedding, customer-facing product traffic, downstream third-party use, or other work outside the approved GTAC scope. Contractors, defense industrial base companies, integrators, cybersecurity vendors, and other non-government entities may use GTAC only to support the approved GTAC scope.


  1. 본인은 접수 양식을 검토하였으며, 적절한 조사와 합리적인 주의를 기울인 결과 제공된 정보가 본인의 지식과 신념에 비추어 정확하고 완전함을 선언하고 확인합니다.

  2. 본인은 고객을 대리하여 본 양식에 서명할 수 있는 권한을 보유하고 있으며, TAC를 추진하는 데 필요한 모든 내부 승인을 취득했습니다.

  3. 본인은 본 접수 양식의 정보 중 어느 하나라도 정확하지 않거나 더 이상 완전하지 않다는 사실을 알게 되는 즉시 서면으로 OpenAI에 통지하겠습니다.

  4. 고객은 본 접수 양식의 법적 약관에 동의하며, 해당 약관은 서비스 계약에 포함됩니다.


참고: 참고: 제출 후에는 정부 발급 신분증 확인과 기본적인 비즈니스 정보 제공을 포함한 간단한 본인 확인 절차를 거쳐야 합니다.