Every ChatGPT Session Is a Data Event
Employees send prompts, attach files, and build custom GPTs in ChatGPT Enterprise, often with regulated or proprietary data inside. Without the right integration, security teams have no visibility into what enters or exits the workspace. This datasheet covers how Cyberhaven's ChatGPT Enterprise Cloud Connector uses OpenAI's Compliance API to monitor that activity and classify sensitive data automatically.
What's inside
What the Connector Monitors
Tracks user prompts, assistant responses, file uploads, and tool invocations across every conversation.
Inspects knowledge files, configuration, and sharing settings for every custom GPT.
Performs content inspection on conversation transcripts and attached files to detect sensitive data.
Setup and Deployment
Requires an OpenAI API key with Compliance API read scope, granted by OpenAI support.
Connects in the Cyberhaven Console using your Workspace ID and API key.
Lets you scope scans by user, GPT, file type, and file size before enabling forward and historical scans.
Data Retention and Limits
OpenAI retains compliance logs for 30 days and chat-uploaded files for only 48 hours.
Historical scans can only reach as far back as OpenAI's 30-day compliance log window.
Image-only messages are not scanned, and events can take up to 30 minutes to appear.