Skip to content
All integrations
ChatGPT

Control sensitive prompts sent to ChatGPT.

Observe ChatGPT use through the Elba browser extension. Configure policies to block supported sensitive prompts and text-file uploads before they are sent.

Browser extension coverage

Product illustration · Example data and workflow.

Capabilities

What this integration covers.

01

Understand how ChatGPT is used.

See browser-observed account states, including work, personal, signed-out, and unknown sessions.

02

Block supported sensitive content.

Use a configured Playbook to block a supported sensitive prompt or text-file upload.

03

Explain the policy to the employee.

Show the employee an in-browser warning, with a finding your security team can investigate.

Example workflow

Block a prompt that matches your data policy.

How the integration supports a specific security task.

  1. 01

    Detect sensitive content

    The enrolled browser extension detects sensitive information in a supported ChatGPT prompt.

  2. 02

    Apply the policy

    A configured Playbook matches the finding and blocks the send.

  3. Explain the block

    The employee sees the warning and your security team can review the browser finding.

Related capability

Explore this part of the platform.

Explore AI & browser security

Before you connect

Coverage, permissions, and requirements.

ChatGPT coverage is observed by the elba browser extension. It is not an OpenAI API or OAuth connector, and browser observations are not verified ChatGPT accounts.

Explore security & privacy
Does elba connect to an OpenAI or ChatGPT account?

No. This coverage comes from the elba browser extension. It observes supported browser interactions and does not create an API or OAuth connection to ChatGPT.

Does elba send detected ChatGPT account details?

The account-state signal does not expose the detected email address or domain, page content, tenant-specific hostname or full URL in elba.

Can elba inspect every uploaded file?

No. Supported text-based files can provide a limited content excerpt. Binary formats expose metadata only, and incomplete inspection does not automatically block the upload.

Is a sensitive prompt or upload always blocked?

No. Blocking requires a supported interaction and an active Playbook configured for the corresponding sensitive-data event.

Coverage and requirements
  • Browser-observed ChatGPT use is not a verified account and does not provide connector-confirmed OAuth access or account-remediation actions.
  • Availability depends on browser, operating system, extension enrollment and the Browser Security configuration shown in your workspace.
  • For binary files—including PDFs, Microsoft Office files, most images and archives—only file metadata is available; their contents are not extracted.
  • Incomplete or unavailable inspection does not by itself block an upload, and a Playbook must be configured for supported blocking behavior.

Other applications

Review more integrations.

All integrations

Discuss your requirements

Evaluate Elba for ChatGPT.

Review the available capabilities, required permissions, and setup for your environment with our team.

Request a demo