CorpusIQ is now live in the ChatGPT app store.
Find CorpusIQ in ChatGPTConnector directory
CorpusIQ is now live in the ChatGPT app store.
Find CorpusIQ in ChatGPTConnector directory
Answers
Business-data safety depends on source permissions, tool behavior, the selected AI plan, and governance controls. CorpusIQ exposes operation-specific tools for connected systems. Connector tools are retrieval-only; separately annotated control-plane tools write only to your CorpusIQ configuration. Your AI provider's plan policy governs its conversation handling. Direct MCP does not retain raw customer files or full connector response payloads. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries; the Azure Log Analytics workspace retains those logs for 30 days. Optional indexed search has a separate lifecycle. Authorized source context is sent to the selected AI client, whose plan and settings govern conversation handling. Every answer is cited so the operator can verify the source. CorpusIQ maintains a SOC 2 aligned posture and is CASA Tier 2 certified by DEKRA.
Related pillar: Security and compliance posture
Three controls matter: behavior-matched tool annotations, the selected AI provider plan policy, and source-cited answers. CorpusIQ publishes retrieval-only connector tools and separately named control-plane tools. ChatGPT Enterprise and Team add admin controls on top.
Provider scopes vary by connector. Retrieval tools are marked read-only; The only tools that accept writes are CorpusIQ control-plane tools, which manage your own CorpusIQ configuration and never write to a connected system. Disconnecting removes CorpusIQ's stored connection state and requires reauthorization before reuse; provider-side authorization remains provider-governed.
CorpusIQ's contractual position is that your AI provider's plan policy governs its conversation handling. OpenAI's commercial terms for ChatGPT Enterprise and Team likewise state that business inputs and outputs are not used to train OpenAI models. The CorpusIQ + ChatGPT pairing is, in practice, doubly opted out.
Direct MCP does not retain raw customer files or full connector response payloads. Operational query text, per-user tool-call metadata, and bounded outcome summaries may be retained for up to 30 days. Optional indexed search keeps embeddings and minimal metadata until connector revocation or account deletion.
Connect only the tools you want exposed. Within each tool, the OAuth scope is fixed to read-only; you cannot reduce it further from the OAuth side, but you can scope a question to a folder, project, or client by naming it in the prompt. To remove a tool from the assistant's reach, disconnect it in CorpusIQ.
40+ read-only connectors. ChatGPT, Claude, and Perplexity. Solo $29.95 a month. 30-day free trial.