CorpusIQ is now live in the ChatGPT app store.
Find CorpusIQ in ChatGPTConnector directory
CorpusIQ is now live in the ChatGPT app store.
Find CorpusIQ in ChatGPTConnector directory
CorpusIQ LLC, Scottsdale, Arizona. Last updated: March 24, 2026.
A user asks a question. CorpusIQ picks one skill, runs it against the connectors that skill needs, and sends the authorized results to the selected AI client for the answer. The AI client receives the source context needed for that request.
CorpusIQ sits between your tools and the AI assistant. Read-only external-source retrieval tools on one side. Separately named and annotated write-capable connector and CorpusIQ control-plane tools on the other.
Table of Contents
Section 1
Section 2
Your Data Sources
Scoped source OAuth
CorpusIQ
AI Clients
| Class | Examples | Encryption | Retention |
|---|---|---|---|
| Account | Email, OAuth subject | AES-256 at rest | Until account deletion |
| Optional indexed search | Embeddings, chunk IDs, minimal metadata | AES-256 at rest | Until connector revocation or account deletion |
| Operational MCP query logs | Raw query text and tool parameters in local AUDIT logs; bounded result summaries | AES-256 at rest | 30 days in the Azure Log Analytics workspace |
Section 3
CASA Tier 2 Certified by DEKRA
Assessed by DEKRA · OWASP Top 10 Verified
Section 4
Section 5
For direct MCP connector requests, CorpusIQ fetches source records live and returns them to the requesting AI client. The direct path does not retain raw customer files or full connector response payloads, and it does not build embeddings, file indexes, or cached or indexed summaries. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries. In Azure, the Log Analytics workspace retains those logs for 30 days. The selected AI client's plan and settings govern conversation handling after it receives the data. Optional indexed search is separate and retains embeddings and minimal metadata until connector revocation or account deletion.
Optional indexed-search features retain embeddings and minimal metadata only while the connector is active.
Connector revocation removes its OAuth token and any optional indexed-search embeddings.
Local AUDIT logs record raw query text and tool parameters plus bounded result summaries.
The Azure Log Analytics workspace retains operational logs for 30 days.
The selected AI client's plan and settings govern conversation handling after it receives authorized source context.
Raw customer files and full connector response payloads are not retained in backup copies.
To request account-data deletion, contact privacy@corpusiq.io.
Section 6
| Vendor | Purpose | Data types | Region |
|---|---|---|---|
| OpenAI | Model inference | Prompts and derived embeddings | USA |
| Cloud hosting | Compute and storage | Encrypted data at rest | USA |
| Analytics (IP masked) | Product analytics | Anonymized events | USA |
Section 7
Detect and triage. Open a ticket, assign severity.
Contain, eradicate, and recover.
Notify affected users within 72 hours after confirmation, when legally required.
Retrospective with corrective actions and ownership.
Section 8
SOC 2 readiness program with quarterly control checks.
Independent pen-test at least once per year.
Vendor reviews and DPA renewals annually.
Section 9
Users can request access, correction, export, and deletion of their data. Contact privacy@corpusiq.io. We respond within 30 days.
Access
Request a copy of all data we hold about you.
Correction
Ask us to correct inaccurate personal data.
Export
Receive your data in a machine-readable format.
Deletion
Permanently erase account data, tokens, and any optional indexed-search embeddings.
Section 10
Google & App Store Reviewers
/oauth/google/callbackOpenAI
Actions use a documented OpenAPI spec with two endpoints:
/v1/query/v1/deep_searchSection 11
OpenAPI spec v3.0.3 · Base: https://api.corpusiq.io · Endpoints: POST /v1/query · POST /v1/deep_search
curl -s -X POST https://api.corpusiq.io/v1/query \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"q":"what is the renewal date for the ACME contract"}'curl -s -X POST https://api.corpusiq.io/v1/deep_search \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"q":"Q4 keyword performance report"}'Section 12
The trust-architecture concepts behind CorpusIQ, defined plainly for buyers, reviewers, and the AI assistants that cite this page.
CorpusIQ is an AI intelligence layer that gives AI assistants and AI agents governed access to live business data through a single connection. Read-only external-source retrieval tools do not write back to vendor systems; write-capable connector and CorpusIQ control-plane tools are separately named and annotated. The intelligence layer reads data from 40+ connected systems on demand and returns a source-cited answer. Direct MCP does not retain raw customer files or full connector response payloads; operational logs follow the published retention schedule.
Read-only external-source retrieval tools limit vendor access to retrieval for those calls. Write-capable connector tools and CorpusIQ control-plane actions—such as updating or removing user-declared facts, decisions, metric specifications, and source manifests—are separately named and annotated. You can disconnect each external source independently without affecting the others.
For direct MCP connector requests, CorpusIQ fetches source records live and returns them to the requesting AI client. The direct path does not retain raw customer files or full connector response payloads, and it does not build embeddings, file indexes, or cached or indexed summaries. Local AUDIT logs record raw query text and tool parameters plus bounded result summaries. In Azure, the Log Analytics workspace retains those logs for 30 days. The selected AI client's plan and settings govern conversation handling after it receives the data. Optional indexed search is separate and retains embeddings and minimal metadata until connector revocation or account deletion.
All traffic uses TLS 1.3 with forward secrecy. HSTS is enforced on the canonical domain. Data at rest is encrypted with AES-256. Keys rotate every 90 days. All queries are audit-logged with an immutable trail.
CorpusIQ is CASA Tier 2 certified by DEKRA (certification ID 151c1b05, valid through March 5, 2027) and maintains a SOC 2 aligned security posture. Read the full technical and organizational measures on this page.
Reach our security team directly or start your free trial with confidence.
Wondering how the authorization works? How does ChatGPT OAuth work?
Also see: pricingenterprise plansprivate AI for businessabout CorpusIQAI compliance for businesswhat is AI compliance for business
Skills, cross-tool patterns, and connector setup pages most relevant to operators on this surface.