Optional AI processing
Last updated 30 August 2026
OpenAI is the only AI provider ConformOps uses, and it is optional.
The workspace master setting and every product setting are off by default. Both must be on before ConformOps can send an OpenAI request. Only a workspace Owner or Admin can change either setting; Members cannot.
What AI is used for
When enabled for a product, OpenAI may produce a cautious proposal for evidence mapping or explanation. The proposal is recorded with its model, prompt version, evidence identifiers, input hash, and result hash. It does not change the deterministic requirement state and cannot approve a risk, close a gap, choose a final legal route, accept an external assessment, sign a declaration, or file a report.
Training and data sharing
OpenAI states that data sent to its API is not used to train or improve OpenAI models unless the API account explicitly opts in to share data. ConformOps does not opt in. Provider calls are also blocked unless the deployment explicitly confirms that optional OpenAI API data sharing is disabled. This training boundary is an OpenAI API account control, not what the ConformOps workspace or product switch changes.
What is sent
The request contains recorded product facts; the deterministic requirement identifiers, obligations, authority effect and locator, current state and conclusion; and sanitized evidence excerpts with evidence identifiers and line spans. Source paths are also sent unchanged because they are provenance. A source path can itself contain a personal name or sensitive filename, so customers should avoid credentials or unnecessary personal data in filenames.
What is not sent
- Raw ZIP archives or whole unfiltered repositories.
- Unsanitized accepted source content.
- Detected confidential secret values, private keys, or tokens.
- Payment-card data.
- Authority to make a final legal or approval decision.
Storage and retention boundary
ConformOps sends Responses API requests with store: false. This disables provider application-state storage for the response, but it is not by itself a Zero Data Retention guarantee. OpenAI may retain abuse-monitoring logs under the API project's data-control terms unless the project is separately approved and configured for Modified Abuse Monitoring or Zero Data Retention. The current code and deployment configuration do not prove either control, so ConformOps does not claim them.
The client currently uses the standard OpenAI API endpoint and does not select eu.api.openai.com. ConformOps therefore does not claim EU-only OpenAI processing. See Data residency.
Turning AI off
Turning the workspace setting off resets every product AI choice to off and prevents a product from enabling OpenAI until the workspace setting is restored. Turning the workspace setting on does not enable any product automatically. A queued run checks the live workspace and product settings again before an OpenAI request, so a later workspace opt-out still blocks that request. A request already in flight cannot be recalled. Turning AI off does not rewrite completed evidence or delete an AI trace already recorded in ConformOps. Permanently deleting the product removes those product-bound traces through the verified erasure procedure. The deterministic CRA engine, OSV correlation, evidence register, gaps, risks, and controlled artifacts continue without OpenAI.
Provider failure
A missing API-data-sharing confirmation, missing configuration, an unevaluated model, a cost-budget refusal, or an unavailable provider leaves the OpenAI proposal empty and the deterministic assessment usable. A model response is accepted only when it uses evidence identifiers from the supplied allowlist and the configured evaluated model identity.