Agent profile · Coding
OpenAI Codex
OpenAI Codex is classified by AgentenCode as a coding agent from OpenAI. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
This agent profile links to a curated provider view. Security controls are not inherited across products.
AgentenTrust 2.0 · EU & governance evidence
Trust, privacy and control evidence for OpenAI Codex
Direct answer: AgentenCode currently documents 12 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.
Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.
Field-level evidence
Documented controls and values from primary sources.
Governance · Audit logs · API
Compliance API access is documented in the enterprise feature matrix.
Scope: enterprise_and_edu · verified 2026-10-01 · Primary source ↗Governance · Audit logs · Available
Enterprise/Edu audit logs are documented in the Codex/ChatGPT feature matrix.
Scope: enterprise_and_edu · verified 2026-10-01 · Primary source ↗Governance · Audit logs · Retention days
The documented Compliance Logs Platform retention window is 30 days.
Scope: enterprise_and_edu · verified 2026-10-01 · Primary source ↗Governance · Audit logs · SIEM export
Codex workspace audit data can be exported into SIEM/data-lake workflows through the compliance interfaces.
Scope: enterprise_and_edu · verified 2026-10-01 · Primary source ↗Governance · Custom roles
Custom roles are documented.
Scope: enterprise · verified 2026-10-01 · Primary source ↗Governance · RBAC
RBAC is documented for Enterprise.
Scope: enterprise · verified 2026-10-01 · Primary source ↗Governance · SCIM
SCIM provisioning is documented.
Scope: enterprise · verified 2026-10-01 · Primary source ↗Governance · SSO · Saml
SAML SSO is documented for managed ChatGPT/Codex workspaces.
Scope: business_and_enterprise · verified 2026-10-01 · Primary source ↗Hosting · Cloud
Codex Cloud is documented.
Scope: chatgpt_plans · verified 2026-10-01 · Primary source ↗Hosting · Local
Codex also has local execution surfaces.
Scope: cli_and_desktop · verified 2026-10-01 · Primary source ↗Privacy · Data residency · Available
Enterprise residency controls are documented.
Scope: enterprise · verified 2026-10-01 · Primary source ↗Protocols · Mcp · Client
Codex can act as an MCP client.
Scope: codex_cli_and_ide · verified 2026-10-01 · Primary source ↗Security · Customer-managed keys
Customer-managed encryption keys are available through OpenAI Enterprise Key Management where supported.
Scope: chatgpt_enterprise_where_ekm_available · verified 2026-10-01 · Primary source ↗Security · Encryption · At rest
Codex under ChatGPT Enterprise inherits the documented enterprise encryption controls.
Scope: chatgpt_enterprise_including_codex · verified 2026-10-01 · Primary source ↗Security · Encryption · In transit
Codex under ChatGPT Enterprise inherits the documented enterprise transport encryption controls.
Scope: chatgpt_enterprise_including_codex · verified 2026-10-01 · Primary source ↗Evidence-backed overview
What is OpenAI Codex?
OpenAI Codex is classified by AgentenCode as a coding agent from OpenAI. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
Product-specific evidence for OpenAI Codex
This profile links 7 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Coding.
Customer-Managed Keys
Yes · Scope: chatgpt_enterprise_where_ekm_available · verified 2026-10-01.
Primary source ↗Verschlüsselung at rest
AES-256 · Scope: chatgpt_enterprise_including_codex · verified 2026-10-01.
Primary source ↗Verschlüsselung in transit
TLS 1.2+ · Scope: chatgpt_enterprise_including_codex · verified 2026-10-01.
Primary source ↗AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.
How to read the evidence
The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.
AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.
Decision context
Provider and category
OpenAI Codex is documented under Coding and is associated with OpenAI. Category labels help navigation but do not replace product-specific evidence.
Verification status
The public profile is marked editorially reviewed and was last checked on October 1, 2026.
Trust coverage
12 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.
Source-first use
For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.
Capabilities, strengths and deployment checks for OpenAI Codex
OpenAI Codex is classified as Coding-Agent from OpenAI. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.
Features implementieren
This use case is part of the stored profile for OpenAI Codex. The related strength is “Mehrstufige Softwareaufgaben”. In a production evaluation, the practical boundary to verify is: Codeänderungen vor Merge überprüfen.
Bugs beheben
This use case is part of the stored profile for OpenAI Codex. The related strength is “Arbeit mit bestehenden Repositories”. In a production evaluation, the practical boundary to verify is: Secrets und produktive Zugangsdaten schützen.
Code verstehen
This use case is part of the stored profile for OpenAI Codex. The related strength is “Editor- und Terminalnähe”. In a production evaluation, the practical boundary to verify is: Tests und Security-Checks nicht überspringen.
Tests und Refactoring
This use case is part of the stored profile for OpenAI Codex. The related strength is “Delegierbare Aufgaben”. In a production evaluation, the practical boundary to verify is: Codeänderungen vor Merge überprüfen.
What to verify before adoption
- Codeänderungen vor Merge überprüfen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Secrets und produktive Zugangsdaten schützen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Tests und Security-Checks nicht überspringen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Verified history
The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.
- October 1, 2026 · Source Maintenance
- September 30, 2026 · Verification Update
- September 28, 2026 · Schema Upgrade
Official sources
This profile links 7 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.
- OpenAI Developers – Codex
- OpenAI Developers – ChatGPT and Codex pricing/features
- OpenAI – ChatGPT Work admin FAQ
- OpenAI – Compliance API
- OpenAI Developers – Docs MCP
- OpenAI – Business data privacy, security, and compliance
- OpenAI – ChatGPT Work Overview
Frequently asked questions
What is OpenAI Codex?
OpenAI Codex is listed by AgentenCode as a coding agent or agentic product from OpenAI.
How much trust evidence is documented for OpenAI Codex?
The current trust layer documents 12 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.
When was this profile last checked?
The current profile verification date is October 1, 2026. The linked primary sources remain authoritative if the product changes between checks.
