Skip to content
CISO Marketplace Services

OpenAI Trusted Access for Cyber · verified

The cybersecurity firm that bet on AI from day one is now TAC verified.

QSai LLC and CISO Marketplace are verified under OpenAI's Trusted Access for Cyber program: identity-verified access to GPT-5.3-Codex and Codex Security for legitimate cybersecurity work. We are opening partner places to practitioners who want to deliver at that access tier.

What the partnership means

TAC verification is a capability unlock. Here's what partners get.

Standard API access hits safety throttles on dual-use cyber queries. TAC-verified access removes that friction for identity-verified practitioners doing legitimate security work, and partners on our bench benefit from our verified status.

TAC program guidance and onboarding

CISO Marketplace is verified under OpenAI's Trusted Access for Cyber program. We share practical guidance on what verification involves, what it unlocks and how to position TAC-level access in engagements, from a team that has been through it.

GPT-5.3-Codex access in engagements

Partners on our delivery bench benefit from our TAC-verified access when staffed on client engagements: Codex Security and GPT-5.3-Codex at full capability, without navigating verification independently first.

Platform presence and lead flow

CISO Marketplace surfaces across its ecosystem and the CyberAdX network. Partners on the delivery bench are matched to enterprise leads coming in through our OpenAI and Anthropic channels, leads that already understand AI-augmented security.

Staffing on TAC-verified engagements

The clearest benefit: qualified partners join our delivery bench for GPT-5.3-Codex-powered client work (application security assessments, Codex Security deployments, compliance automation and vCISO advisory). Real, paid engagements.

Read: what TAC verification means in practice ↗

Access tiers

What TAC verification unlocks.

OpenAI's Trusted Access for Cyber program has distinct tiers. CISO Marketplace is TAC Verified today, and is pursuing the GPT-5.4-Cyber tier.

Standard

Standard API access

Public OpenAI API access. Dual-use cybersecurity queries hit automated safety throttles, and the model may silently route to a fallback.

  • Standard-tier OpenAI API access
  • Throttled on dual-use cyber queries
  • May route to a fallback model
  • No identity verification
TAC VerifiedOur current status

Trusted Access for Cyber

Identity-verified access to GPT-5.3-Codex and Codex Security, with reduced friction across dual-use cyber capabilities and a full accountability framework.

  • GPT-5.3-Codex, full capability
  • Codex Security application scanning
  • Identity-verified operator status
  • Dual-use capabilities unlocked
  • Reduced throttling for legitimate work
GPT-5.4-CyberPursuing access

Cyber-permissive tier

The next tier, rolled out to vetted security vendors and researchers. Clients and partners get first access if ours is confirmed.

  • Everything in TAC Verified
  • Binary reverse engineering, no source needed
  • Lower refusal boundaries for security work
  • Advanced defensive workflow support
  • Supply chain compiled-binary analysis

Our story

Rebuilt around AI, then verified by both frontier labs.

CISO Marketplace is a solo-founded, self-funded cybersecurity operation that rebuilt entirely around AI after Vulsec, our previous firm, closed during COVID. Andrew Ostashen, Managing Member, has run offensive security assessments across healthcare, energy and the Fortune 100.

We received TAC verification the same day OpenAI announced it was scaling the program to thousands of verified defenders. The operational record Anthropic reviewed for our Claude partner application is the record OpenAI reviewed for TAC: AI-built properties, the MicroSec Tools catalog, and client deliverables built on frontier models.

We don't know of another independent vCISO practice with verified status at both Anthropic and OpenAI.

Prefer Claude? The Claude partner practice →General partner program (no AI requirement) →

Who we're looking for

  • Consultants and vCISOs deploying GPT-5.3-Codex on client work
  • GRC and compliance practitioners automating evidence and policy workflows
  • Security architects building AI-native detection and response pipelines
  • Application security engineers running Codex Security repository scans
  • Offensive security practitioners augmenting assessments with TAC-tier AI
  • Anyone who wants to be staffed on TAC-verified security engagements

Ready to deliver at the TAC tier?

Staffing on real, TAC-verified engagements. Tell us about your practice.

Apply now →
Talk to an advisor
Advisor