30 Days Gen AI Risk Trial -Start Now
Book a demo
Chatbots·Free·chatgpt.com

ChatGPT

OpenAI's flagship conversational AI assistant powered by GPT models; writes, codes, reasons, browses, runs agents, and creates images/video across web, mobile, and desktop.

Risk Score
Critical
9/10

Independent assessment across data handling, compliance, security and transparency.

Overview

ChatGPT is OpenAI's consumer and enterprise chat assistant built on the GPT family of models. It handles writing, research, code generation, image and video creation (Sora), voice chat, file analysis, Deep Research, and agentic task execution via Agent Mode. It is the most widely adopted generative-AI product in the enterprise, available in Free, Go, Plus, Pro, Business, Enterprise, and Edu tiers. Business and Enterprise plans add SSO, admin controls, a signed DPA, SOC 2 Type II scope, and a contractual no-training default, while consumer tiers train on user data unless the user toggles it off.

Risk factors

3
  • Trains on user inputs by default unless opt-out is enabled
  • No Data Processing Agreement available
  • No SOC 2 attestation for free tier

Recommendations

3
  • Block on enterprise networks if used for sensitive data
  • If allowed, require users to disable training in chat history settings
  • Migrate users to Team or Enterprise for compliance work

Data handling

Storage
Stored in OpenAI-managed infrastructure (primarily AWS/Azure US); ChatGPT Enterprise and API offer regional data residency in the EU, UK, Japan, Korea, Singapore, India, Canada, and Australia.
Retention
Indefinite unless user deletes
Training on inputs
On by default; user must opt out per chat