Every prompt, response, tool call and uploaded file from your
OpenAI workspace, turned into evidence for your auditors.
Read-only, nothing is blocked, returned or deleted.
INTERACTIONS SCANNED / DAY · LAST 16 DAYS
Detector breakdown
Frameworks mapped
Inline guardrails need to own the request path. ChatGPT Enterprise is a third-party application, so there is nothing to sit inside, this reads the record of what already happened, across the whole workspace, and evaluates all of it.
Inline guardrails need to own the request path, and nobody owns ChatGPT's. This reads the record of what already happened, across the whole workspace, and evaluates all of it.
EU AI ActMapped
ISO/IECMapped
MITRE ATLASMapped
NIST AI RMFMapped
OWASP LLM Top 10MappedContent is scanned; metadata is not. File names, tool names, model IDs and client types are used for grouping only and never sent to a detector.
Every scan produces a single view of where your workspace stands, in the sections your security, legal and audit teams work from. Not a message count in an admin console.
Injection attempts, policy violations, total violations and flag rate, with the usage context: messages, conversations, users, models, sources and uploaded files in the selected window.
The flagged message, with PII redacted. Open a row for the whole conversation around it, with its detector, service, direction and timestamp.
Policy Violation reports which numbered rule was broken, grouped as counts and as a share of the total, so concentrated exposure is obvious.
Where the risk sits across ChatGPT, Codex, custom agents, connectors and the spreadsheet plugin. A source that was never ingested reads differently from one that came back clean.
Violations mapped to the EU AI Act, ISO/IEC, MITRE ATLAS, NIST AI RMF and the OWASP LLM Top 10, so the evidence arrives in your auditors' language.
Repeat every 7 or 14 days so each run picks up where the last ended, well inside the retention window. Build a report across every scan and provider: a single report only covers its own window, this spans them.
Illustrative scan figures, sample workspace, not customer data
Each square is one service-day inside the 30-day retention window. Red squares carried an injection attempt; amber ones carried a policy violation, that is the list your compliance team works this week.
FLAG RATE · 2.7% · INBOUND 61% · OUTBOUND 39%
Retrospective and read-only. It reads the record of what already happened and evaluates all of it. Nothing is blocked, written or deleted, remediation stays with your admins.
EU AI ActART. 9 · 10 · 15Mapped
ISO/IEC 42001CLAUSE 6 · 8 · ANNEX A.9Mapped
MITRE ATLASAML.T0051 · AML.T0057Mapped
NIST AI RMFGOVERN · MAP · MEASURE · MANAGEMapped
OWASP LLM Top 10LLM01 · LLM02MappedThe 30-day retention window is the whole design constraint. Scan on a recurring interval well inside it and each run picks up where the last one ended.
deletedetect API, run in your own application's request path and can block or redact in real time. That depends on owning the request path, and nobody owns ChatGPT's. This integration is workspace-wide rather than request-scoped, and retrospective rather than preventive. Used together, the two cover both sides of your OpenAI footprint: this for the workspace your employees use, the detect API for the applications your engineers build.If your organisation runs ChatGPT Enterprise, we will show you what is really happening inside it, with your own policies in place. A Compliance API key and a workspace ID is all it takes to start.
