← All posts

Newsdata protectionDLPDSPMdata security

Cyberhaven Extends Data Security Platform into ChatGPT Enterprise and Claude via Compliance APIs

Cyberhaven has extended its data and AI security platform with new compliance-API integrations for OpenAI’s ChatGPT Enterprise and Anthropic’s Claude Enterprise, giving security and compliance teams visibility into conversations, uploaded files, and workspace activity inside both tools.

The DLP angle is what makes this worth a look. The integrations use the ChatGPT Enterprise Compliance API and Claude Compliance APIs to monitor, inspect, and classify sensitive data already inside each platform — data at rest in the AI tool, not just data in motion. Traditional browser and endpoint controls can inspect content as it moves into an AI application, but they can’t always see what already lives in Claude or ChatGPT Enterprise: historical conversations, uploaded files, custom GPT and Projects configurations, sharing permissions, and user activity.

By layering data discovery, classification, and incident response directly onto both platforms, Cyberhaven is effectively bolting a DSPM-style posture layer for GenAI workspaces on top of its existing endpoint and browser DLP. For buyers, the practical question is whether API-based retrospective scanning of AI transcripts becomes a checkbox every DLP/DSPM vendor now has to match — and how it slots in alongside runtime prompt controls of the kind we’ve tracked from Microsoft Purview and Fortinet.

Caveat for practitioners: this is a vendor product announcement, so treat capability and adoption claims as vendor-supplied until independent testing lands. The core idea — governing what’s already accumulated inside enterprise AI tools, not just what’s flowing in — is a gap most endpoint-first DLP stacks still have.