Book a Demo
All coverage

Coverage

OpenAI / ChatGPT

See what your organisation actually asks ChatGPT

ChatGPT Enterprise and the OpenAI API platform are two different surfaces with two different risk profiles — one serves your workforce, the other your applications. SAF3AI connects to both through OpenAI's own compliance and audit interfaces, and puts them on one graph.

Connects via Compliance + Audit Log APIs
Access model Read-only API keys
Time to first signal Under an hour
User impact None — nothing to install

The telemetry we pull

ChatGPT compliance logs

Conversations, uploaded files, GPTs and workspace activity from ChatGPT Enterprise and Edu — the record of what was actually asked and shared.

Platform audit logs

Administrative events from the OpenAI API platform: members added, projects created, API keys minted or revoked, settings changed.

Stored completions

Request and response pairs retained on the API platform, giving prompt-level visibility into what your applications send to the models.

Usage and cost

Token consumption and spend by project, API key and model — attributed back to the team that owns the workload, not a single line on a corporate invoice.

Project and key inventory

Every project, service account and API key as a tracked non-human identity, with the owner and the scopes attached.

Custom GPTs and assistants

The GPTs your organisation has built, what data they were given and who can reach them — the shadow-agent problem inside the sanctioned tenant.

From zero to first signal

  1. 1

    Identify which OpenAI surfaces you run

    Most organisations have both: ChatGPT Enterprise for people and the API platform for applications. They authenticate separately and SAF3AI connects to each independently.

  2. 2

    Generate the credentials

    ChatGPT Enterprise uses a Compliance API key from workspace settings. The API platform uses an admin key for audit logs, usage and costs. Both are read-only.

  3. 3

    Add them in Integrations

    Paste the keys into the connector. They are encrypted at rest, scoped to your tenant, and redacted anywhere they would otherwise surface in the UI or logs.

  4. 4

    Backfill and stream

    History is pulled first so the dashboard is populated on day one, then the connector polls continuously against a durable watermark that survives restarts without gaps or duplicates.

  5. 5

    Correlate across the estate

    OpenAI projects, keys, GPTs and users become entities in the Context Graph, so the same person exfiltrating through ChatGPT and through Copilot is one incident, not two.

Compliance log access requires a ChatGPT Enterprise or Edu workspace. An API-platform-only tenant still gets audit logs, usage, cost, stored completions and full key inventory.

Risks specific to this surface

Regulated data in prompts

PII, PHI, PCI and source code pasted into ChatGPT. Detection uses validated recognisers — mod-97 IBAN checks, SSA-rule SSNs, entropy analysis on tokens — so the findings survive review.

API keys with no owner

Long-lived platform keys that outlast the project or the employee. Every key is inventoried as a non-human identity with an owner, a scope and a last-used time.

Custom GPTs built on sensitive data

An internal GPT grounded in an HR or finance corpus and shared workspace-wide. The graph shows what data each GPT can reach and who can reach the GPT.

Runaway model spend

A retry loop or an unbounded agent burning tokens for days. Per-project budgets and anomaly alerts fire on the spend curve rather than the invoice.

Prompt injection in retrieved content

Instructions embedded in documents or web content that an assistant then follows. Detected on the content, including hidden and bidirectional-override text.

Consumer ChatGPT beside the enterprise tenant

People on personal accounts to dodge workspace controls. Shadow AI discovery sees what the Enterprise connector structurally cannot.

See OpenAI / ChatGPT in your own tenant

Connect this surface in a pilot and get a mapped inventory, a scored risk list and the attack paths that actually reach your data.