This came up with my first search "openai security":
https://trust.openai.comAt the bottom is a link to report an issue. Seems like there are multiple ways to report issues. And they come with the potential for bug bounties.
And so many companies don't follow the security.txt standard that it puts OpenAI well ahead of most companies.