OpenAI

OpenAI Compliance Platform for Enterprise and Edu Customers

Obtain audit and compliance data in your workspace.

Updated: 16 hours ago

Compliance API documentation

The Compliance API documentation can be found here. Please note that you must be logged into your Enterprise or Edu workspace to view the API documentation.

How to get access

The Compliance Platform is available to Enterprise and Edu customers. If you'd like to purchase a plan for your organization, please reach out to our sales team or your account manager.

How it works

The Compliance Platform provides access to logs and metadata from your ChatGPT workspace that you can connect with your eDiscovery, DLP, or SIEM tools.

The Compliance Platform supports two complementary access patterns:

  • Compliance Logs Platform for immutable, append-only compliance log events for auditing purposes.

  • Stateful Compliance API for querying state at the time of request. These are useful for joining data referenced from events above and for legacy data types for audit purposes.

You can use the API Documentation and quickstart notebook to learn how to ingest data into your SIEM or data lake.

eDiscovery tools help in identifying, collecting, and delivering electronic information that can be used as evidence in legal cases.

  • Organizations use these tools during litigation, investigations, or audits. They enable legal teams to sift through large volumes of data to find relevant documents and communications efficiently.

DLP (Data Loss Prevention) tools are used to detect and prevent data breaches, data exfiltration, and the unauthorized use or access to sensitive information within an organization.

  • They are commonly used to protect intellectual property and ensure compliance with privacy laws and regulations such as GDPR, HIPAA, etc. DLP systems monitor, detect, and block sensitive data while in-use (endpoint actions), in-motion (network traffic), and at-rest (data storage).

SIEM (Security Information and Event Management) tools provide real-time analysis of security alerts generated by applications and network hardware.

  • They are used for threat detection, security incident management, and compliance. By aggregating and analyzing log data, SIEM systems help identify anomalous behavior and potential threats.

Data Retention with the Compliance API

The Compliance Logs Platform retains data for 30 days. If longer retention is desired then consumers should implement a system to continuously download all logs and retain them according to their policies.

Deleted data is not recoverable. This API does not provide the capability for deleting any data logged internally specifically for audit or security within OpenAI. All authenticated requests to this API are logged for security and compliance purposes. When an item is deleted using this API, it is also removed from all production search and retrieval indexes. Data is retained internally for no greater than 30 days following a deletion request.

Deprecation Notice

On **March 5th, 2026 **a new conversations logs system was released, deprecating the old stateful route.

Action May Be Required: the stateful route was be removed on June 5th, 2026. Please follow the API Documentation to move your integrations to the new source as soon as possible.

Partner Integrations

To help meet their compliance requirements, customers can use Compliance API integrations from eDiscovery, data loss prevention (DLP), and security providers.

Updated conversation message logs in the Compliance Logs Platform are currently supported by:

All partners support ingestion of the other data types. You can read more about the Compliance API in our blog post.

Partner Setup Guides

Getting support for Compliance API partner integration issue

If you experience an issue while using the Compliance API partner integration start by contacting the partner service provider. The partner service provider has visibility into their integration behavior and can determine whether the issue is partner-side or may require OpenAI Support.

Customer using the partner integration

  1. Contact your Compliance API partner first and make sure to include workspace account owners in the email.

  2. When contacting the partner service provider, include the following information

    1. Workspace ID

    2. Screenshot of error observed in the partner service

    3. Full error message

    4. Date/time and timezone on when the issue started

  3. If the partner determines that the issue may be related to the Compliance API or OpenAI configuration, the partner will open a case with support@openai.com.

    1. Make sure you and an account owner of the workspace is included in the support case created by the partner. 

  4. Once included in the support case created by the partner, the workspace account owner must explicitly confirm that OpenAI Support may review workspace specific details provided by the partner.

Partner Integrators

  1. Customers using your integration will contact you first when they experience an issue in the integration service.

  2. Troubleshoot the reported issue and determine whether it is caused by the partner integration or may be related to OpenAI or the Compliance API.

  3. If the issue appears to be related to OpenAI or the Compliance API, open a support case with support@openai.com and include the following. The end customer should not need to open a separate support case or act as an intermediary between OpenAI and the partner.

    1. customer’s Workspace ID

    2. Error details suggesting the issue may be related to OpenAI or the Compliance API

      1. Full error message

      2. Request id

      3. Date/time with timezone of the affected request

    3. Whether the issue affects one customer or multiple customers

    4. Make sure to include the user who reached out as well as the account owner provided by the customer in the support ticket

  4. Further troubleshooting should continue in one shared support thread between OpenAI Support, the end customer, and the partner integrator.

Was this article helpful?