OpenAI×Enkrypt AIEnkrypt AIOfficial OpenAI compliance partner

Compliance monitoring for
ChatGPT Enterprise

Every prompt, response, tool call and uploaded file from your OpenAI workspace, turned into evidence for your auditors.
Read-only, nothing is blocked, returned or deleted.

CHATGPTCODEXCUSTOM AGENTSCONNECTORSSPREADSHEET
5
Log families read through the Compliance API
ChatGPTCodexAgentsConnectorsSpreadsheet
5
Detectors, including your own policy rules
InjectionPolicyPIIToxicityNSFW
30d
OpenAI retention window each scan works inside
Every 7dEvery 14dEvery 30d
5
Compliance frameworks violations map to
EU AI ActISO/IECNISTOWASPMITRE
How it works

Every surface, read after the fact

Inline guardrails need to own the request path. ChatGPT Enterprise is a third-party application, so there is nothing to sit inside, this reads the record of what already happened, across the whole workspace, and evaluates all of it.

The integration

Read. Evaluate. Evidence. Map.

Inline guardrails need to own the request path, and nobody owns ChatGPT's. This reads the record of what already happened, across the whole workspace, and evaluates all of it.

How it runs
1ReadFive log families throughthe OpenAI Compliance API2EvaluateFive detectors, one passover the record + your policy3EvidenceFlag rate, violations,per-service breakdown4MapEU AI Act, ISO/IEC, MITRE ATLAS,NIST AI RMF, OWASP LLM Top 10
compliance-api · log export · sample workspace
Read compliance logs read scope · no delete
Log families read · last 7 days
5 / 5
CONVERSATION_MESSAGE18.4 MB
CODEX_LOG6.1 MB
CUSTOM_AGENTS_LOG3.2 MB
APP_LOG2.7 MB
CHATGPT_PLUGIN_SPREADSHEET0.9 MB
DEDUP44,118 events · de-duplicated on event ID Complete
guardrails · detectors · one pass over the record
Evaluate the record
injection_attackOn
policy_violation · your numbered rulesOn
piiOn
toxicityOn
nsfwOn
VIOLATION · policy_violation · rule 1 "no customer information or internal documents" · conversation 6a4f727a… · inbound · ChatGPT web
✓ EVIDENCE · full flagged message, surrounding conversation and conversation ID attached
dashboard · flag rate · 12 scans
Review findings last 90 days
FLAG RATE PER SCAN · 12 SCANS · SAMPLE DATA
Injection attempts
146
Policy violations
892
Flag rate
2.7%
TOP USERu_2841 · 37 violations across 3 rules Admin review
compliance · framework mapping
Map to frameworks
EU AI ActMapped
ISO/IECMapped
MITRE ATLASMapped
NIST AI RMFMapped
OWASP LLM Top 10Mapped
146 INJECTION → OWASP LLM01 494 PII → EU AI ACT ART. 10 892 POLICY → NIST GOVERN
REPORTBuild report · 1,204 violations · across every scan Complete
Coverage

What the scan actually reads

Content is scanned; metadata is not. File names, tool names, model IDs and client types are used for grouping only and never sent to a detector.

Coverage
User prompts
Model responses
Custom instructions
Quoted text
Attached files
Deliverables

What you get

Every scan produces a single view of where your workspace stands, in the sections your security, legal and audit teams work from. Not a message count in an admin console.

Key metrics

Injection attempts, policy violations, total violations and flag rate, with the usage context: messages, conversations, users, models, sources and uploaded files in the selected window.

MetricValueWindow
Flag rate2.7%Last 7 days

Violations

The flagged message, with PII redacted. Open a row for the whole conversation around it, with its detector, service, direction and timestamp.

ConversationDetectorServiceDirection
6a4f727a…Injection AttackChatGPTInbound

Policy violations by rule

Policy Violation reports which numbered rule was broken, grouped as counts and as a share of the total, so concentrated exposure is obvious.

RuleRule textCountShare
Rule 1Customer records41246%

Detections by service and detector

Where the risk sits across ChatGPT, Codex, custom agents, connectors and the spreadsheet plugin. A source that was never ingested reads differently from one that came back clean.

ServiceEvent typeStatus
CodexCODEX_LOGIngested

Framework violations

Violations mapped to the EU AI Act, ISO/IEC, MITRE ATLAS, NIST AI RMF and the OWASP LLM Top 10, so the evidence arrives in your auditors' language.

FindingFrameworkControl
InjectionOWASPLLM01

Recurring compliance scan

Repeat every 7 or 14 days so each run picks up where the last ended, well inside the retention window. Build a report across every scan and provider: a single report only covers its own window, this spans them.

ScheduleRepeatsStatus
Recurring compliance scanEvery 7 daysRunning

Illustrative scan figures, sample workspace, not customer data

Scan window

44,118 interactions, and the
ones that actually matter

Each square is one service-day inside the 30-day retention window. Red squares carried an injection attempt; amber ones carried a policy violation, that is the list your compliance team works this week.

Clean Policy violation Injection attempt
One scan, narrowed down

From 44,118 interactions
to 146 injection attempts

44,118interactions scanned
1,204flagged by at least one detector
146injection attempts, 3 inside uploaded files

FLAG RATE · 2.7%  ·  INBOUND 61%  ·  OUTBOUND 39%

"
Retrospective and read-only. It reads the record of what already happened and evaluates all of it. Nothing is blocked, written or deleted, remediation stays with your admins.
Design principle · Enkrypt AI × OpenAI Compliance API
Evidence in the language your auditors use
Limitations and considerations

Built to run on a schedule

The 30-day retention window is the whole design constraint. Scan on a recurring interval well inside it and each run picks up where the last one ended.

Read scope onlyEnkrypt never requires delete
De-duplicatedOn the stable event ID, delivery is at-least-once
Up to 30 min latencyBefore an event appears in a compliance log file
File URLs expireScan regularly to capture uploaded file contents
Read-only, alwaysNothing is written, blocked or deleted in your workspace

Questions security teams ask

How is this different from your inline guardrails?
Inline guardrails, the Enkrypt detect API, run in your own application's request path and can block or redact in real time. That depends on owning the request path, and nobody owns ChatGPT's. This integration is workspace-wide rather than request-scoped, and retrospective rather than preventive. Used together, the two cover both sides of your OpenAI footprint: this for the workspace your employees use, the detect API for the applications your engineers build.
Does this change anything for our end users?
No. The integration reads compliance logs on the administrative side. No plugin, no browser extension and no change to the ChatGPT experience.
Do you need delete permissions?
No, the read scope only. Access is granted per API key, so a rotated key needs a new request. Setup is an Admin API key with Compliance API read scopes plus the workspace ID from chatgpt.com/admin/settings.
What are the operating constraints?
OpenAI retains compliance logs for 30 days, and chat-uploaded file URLs expire sooner. Events can take up to 30 minutes to appear, endpoints are rate limited per key, and delivery is at-least-once, so every event is de-duplicated on its stable event ID before anything is scanned. Schedule recurring scans well inside the 30-day window.
Whose policies does the policy-violation detector use?
Yours. A policy is a numbered list of rules defined on the Enkrypt AI platform, so it reflects your organisation's AI usage guidelines rather than a generic ruleset. Each violation names the rule that was broken, and the dashboard aggregates violations by rule.
What about Claude?
Anthropic also exposes a compliance API for claude.ai. It is a live REST API with roughly one-minute latency and cursor-based pagination rather than OpenAI's batch file export, and its chats, uploaded files, artifacts and project instructions are documented as monitorable content. Ask us about Claude coverage on your walkthrough.

Know where you stand

If your organisation runs ChatGPT Enterprise, we will show you what is really happening inside it, with your own policies in place. A Compliance API key and a workspace ID is all it takes to start.