SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service
SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service
SHIM
Contact UsFeaturesPricing
How to Start
BlogAbout UsDocs
Playground
Back to Blog|Home
Compliance

The 30-Day Clock: Governing PII in ChatGPT Enterprise Before the Evidence Disappears

OpenAI's compliance logs are retained for only 30 days. If you can't prove what personal data your team shared in ChatGPT Enterprise within that window, the audit trail is gone for good. Here's how SHIM captures it continuously — and stores findings, never your content.

June 27, 20267 min read

There is a detail in OpenAI's enterprise compliance offering that should change how every regulated firm thinks about ChatGPT governance, and almost nobody has internalized it: the OpenAI Compliance Logs Platform retains your data for 30 days.

Read that again with a compliance hat on. If a KVKK or GDPR question lands about what your staff shared in ChatGPT Enterprise five weeks ago, the source data may simply no longer exist. There is no "pull the archive." A window you did not capture is gone — permanently. OpenAI's own guidance is explicit: if you want longer retention, youmust build a system that continuously downloads and keeps the logs. That single fact turns ChatGPT compliance from a "we'll get to it" project into a clock that is already running.

The same blind spot, on a timer

The underlying gap is the one every regulated firm now has with sanctioned AI. Your employees use ChatGPT Enterprise because you gave it to them — the responsible alternative to consumer ChatGPT. But the usage is a stream of free text: a customer record pasted to draft a response, a spreadsheet of account numbers dropped in for analysis, a Codex session that includes a production secret. None of your existing controls see the content of that:

  • Your API gateway governs developer traffic, not browser chat.
  • Your DLP was built for files and email, not pasted conversation turns inside SaaS.
  • Your SIEM ingests OpenAI's admin and authentication events — logins, not personal data.

So far this is identical to the Claude Enterprise blind spot we cover in the companion piece. What makes OpenAI different — and more urgent — is the 30-day window underneath it all. With Claude, the provider keeps the history; you can catch up. With OpenAI, catching up is not possible. Either you capture continuously, or the evidence ages out.

Continuity is the entire product

Most "export your AI logs" approaches are periodic: someone runs a script, downloads a batch, files it away. Against a 30-day clock, periodic is dangerous. Miss a run because a token expired, a cron failed, or nobody owned the job over the holidays, and you have quietly created a permanent hole in your audit trail — one you will not discover until an auditor asks about exactly that period.

SHIM's ChatGPT Enterprise connector is engineered around the assumption that the gap is the failure mode. Concretely:

  • Continuous capture with checkpoints. SHIM ingests the configured OpenAI Compliance Logs Platform streams for your workspace or organization. It defaults to AUTH_LOG; configured event_types and content_event_types can include conversation, upload, admin, authentication, and Codex events. Per-stream checkpoints resume from the last confirmed position after a restart.
  • Backfill on day one. When you connect, SHIM pulls the entire window still available within retention, so you start with history, not a blank slate.
  • The poller watches itself. Because the cost of falling behind is permanent data loss, the health of the capture pipeline is a first-class, alertable signal. SHIM tracks how much of your retention budget remains and alerts you before lag eats into the danger zone — not after the data is gone.

That self-monitoring is the difference between a control you can attest to and a script you hope ran.

What happens to the data — no raw provider content at rest

The obvious fear is that "continuous capture" means a vendor now hoards a rolling copy of everything your staff typed into ChatGPT. SHIM does not: content is pulled into memory, scanned, and immediately discarded. Findings and activity metadata persist; raw conversations and matched sensitive values do not. Actor identifiers such as email address, user ID, or IP address may be retained as metadata for investigation.

  • entity type and severity (e.g. CREDIT_CARD, critical);
  • the KVKK category (Finansal / Kişisel Veri) and the GDPR category;
  • the location within the content unit (offset and length);
  • a salted, one-way hash of the matched value, for de-duplication and counting only;
  • and the context: actor, model, timestamp.

You get a record that a credit-card number was shared in ChatGPT on this date by this user without storing the raw conversation or matched card number. Actor metadata remains tenant-isolated, and stored provider keys use the configured encrypted secret backend.

The detection that matters here

The capture pipeline is only as good as what it can find. SHIM runs the same high-recall PII engine across ChatGPT content that powers our inline gateway — Microsoft Presidio plus custom recognizers built for Turkish and EU finance: TR TCKN and VKN, IBANs, credit-card numbers, API keys and secrets, emails, phone numbers, and more. Conversation content is scanned turn by turn, so a finding points to the exact place the exposure happened.

What you get out of it

The same four outputs as the rest of the SHIM governance platform, so ChatGPT exposure lands in the workflows your team already uses: a findings dashboard (filter by severity, entity, actor, model, date), SIEM / webhook forwarding (normalized, signed events into Datadog, Splunk, or your stack), real-time alerting (Slack or email on threshold, plus the pipeline-health alerts unique to the 30-day model), and the KVKK Exposure Report(PDF and CSV: counts by severity and category, top exposed entity types, per-employee breakdown, methodology note — the artifact you hand an auditor or attach to a DPIA).

Why SHIM, specifically

It is KVKK-native. TCKN and VKN are first-class entities and findings are classified against KVKK's own categories — not a US/GDPR tool with Türkiye bolted on. It is one pane for every vendor: the same architecture covers Claude Enterprise and ChatGPT Enterprise, so you govern both in a single control plane with one report format. And it is built for the constraint that defines this problem:OpenAI's 30-day window is not a detail we work around — it is the thing the connector is designed for. Continuity, backfill, and self-monitoring are not nice-to-haves here; they are the reason it works.

Don't start the clock late

The uncomfortable truth about ChatGPT Enterprise governance is that every day you do not capture is a day you can never get back. The firms that breeze through their next AI-usage audit are the ones capturing continuously now; the ones that wait will be reconstructing a record that no longer exists. If your team runs ChatGPT Enterprise, the 30-day clock is already running whether or not anyone is watching it.

See SHIM capture it against your own workspace →

SHIM is a B2B AI gateway and governance platform for regulated industries. The gateway redacts PII inline on application traffic; Compliance Connectors give you detective findings and activity metadata for employee enterprise-AI usage — ChatGPT Enterprise and Claude Enterprise — in a single KVKK/GDPR control plane.

Back to all articlesGet Started Free
SHIM

The enterprise-grade AI Gateway for security-conscious teams. Protect your data, govern spend, and account for usage.

Read Documentation→

Product

  • Features
  • Security
  • Pricing
  • Docs

Company

  • About Us
  • Blog
  • Playground
  • Contact Us

© 2026 SHIM Inc. All rights reserved.

SecurityPrivacy PolicyTerms of Service