Changed
·
4
4 changes need your attentionChanges that may affect your rights or add new obligations.
0
0 changes in your favorImproved clarity, better protections, or expanded rights.
6
6 minor changesFormatting, typos, or clarifications with no material impact.
Free preview. Showing 1 of 10 redlines — the most consequential change. The other 9 are available with a free email signup.
Annual pen tests stop covering corporate systems
For systems containing customer content, an external vendor may conduct security penetration tests on the corporate and cloud environments annually to detect network and application security vulnerabilities.
BadChanges that may affect your rights or add new obligations.Corporate systems are no longer explicitly covered by the annual external penetration-test commitment.
9 MORE REDLINES IN THIS UPDATE
§ 4.3 Subprocessor disclosure window
Notification window for new subprocessors reduced from 30 days to 7 days, limiting customer review time before changes take effect.
§ 8.1 Output ownership and licensing
Model output ownership clarified: vendor retains a perpetual license to use customer prompts and outputs for safety research.