Guide · ChatGPT

How to use ChatGPT for vendor risk assessment. With live data from ClauseTrail.

Ask ChatGPT about a vendor's subprocessors and it answers from what it read months ago. Connect ClauseTrail and OpenAI's agent reads the vendor's current list, DPA terms and AI terms instead, with the sentence each answer comes from. Here is how to set it up with Codex, which comes with your ChatGPT plan, or with the OpenAI API.

Add your vendors to ClauseTrail and create an API key. Then add ClauseTrail to Codex, OpenAI's agent included with paid ChatGPT plans, or to the OpenAI API's MCP tool. Ask about your vendors in plain words and it answers from their own documents. Connectors inside the ChatGPT app need OAuth sign-in, which ClauseTrail does not support yet.

Which of our vendors started sending data to an AI provider this quarter?

Codex · used ClauseTrail

Two. Northwind CRM added Anthropic, PBC for email drafting on 12 August, with 30 days to object. Lumen Analytics now names OpenAI for its product assistant, processing in the United States. Neither's AI terms say it trains on customer data.

Answered from ClauseTrail, not model memory

Illustrative thread with fictional vendors.

Step by step

Set up ChatGPT as your vendor risk analyst.

  1. 1

    Add your vendors to ClauseTrail.

    Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so ChatGPT can answer what changed and when.

  2. 2

    Create an API key.

    In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.

  3. 3

    Add ClauseTrail to Codex.

    Codex is OpenAI's agent and signs in with your ChatGPT account. Add ClauseTrail to its config file. You need Node.js installed for the npx bridge.

    Codex (~/.codex/config.toml)

    [mcp_servers.clausetrail] command = "npx" args = ["-y", "mcp-remote", "https://clausetrail.com/mcp", "--header", "Authorization: Bearer YOUR_KEY"]

    Connectors inside the ChatGPT app authenticate with OAuth sign-in, which ClauseTrail does not offer yet, so use Codex or the API for now.

  4. 4

    Ask in plain words.

    Ask what you want to know. Codex picks the right ClauseTrail tool and answers from tracked data, with dates, severities and quotes.

    “Use ClauseTrail to list the changes our vendors made this month that we haven't reviewed, and tell me which one to look at first.”

  5. 5

    Turn the answer into something your team uses.

    Ask for the format you need: a vendor assessment, an objection email to the vendor, a note for the DPO or a table for the auditor. The facts come from ClauseTrail and ChatGPT's writing does the rest.

    “Draft an email objecting to Northwind CRM's new subprocessor, citing the notice period in its DPA.”

  6. 6

    Build it into your own app (developers).

    Add ClauseTrail as a remote MCP tool in the OpenAI Responses API. Your own assistant, Slack bot or procurement tool can then answer vendor questions from the same data.

    OpenAI Responses API tool

    { "type": "mcp", "server_label": "clausetrail", "server_url": "https://clausetrail.com/mcp", "authorization": "YOUR_KEY", "require_approval": "never" }

Workflows to copy

Six vendor risk workflows for ChatGPT.

Weekly vendor brief

What your vendors changed this week, and what to review.

“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”

Your vendors' changes

New vendor assessment

The first pass of a vendor review, from the vendor's own documents.

“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”

Subprocessor lists DPA terms AI terms

DPA comparison

Line up the terms that matter across vendors in one table.

“Compare breach notification, subprocessor notice and deletion after termination across Slack, HubSpot and Notion from ClauseTrail, as a table.”

DPA terms

AI provider inventory

Answer the board's question: which vendors send our data to AI?

“Which of our vendors send data to an AI provider, which providers, and do their AI terms say they train on customer data?”

Who uses a company AI terms

Concentration check

See which companies sit behind many of your vendors at once.

“List the subprocessors most of our vendors share in ClauseTrail, and what would be affected if the top one had an incident.”

Shared subprocessors Dependency graph

Audit trail

The record an auditor asks for, without a spreadsheet.

“List every vendor change since January 1 in ClauseTrail with our decision and who made it, as a table.”

Your vendors' changes

Available over MCP

Everything ChatGPT can read from ClauseTrail.

10 read-only tools on ClauseTrail's MCP server. ChatGPT chooses the right one from your question, so you never call them by name.

Your vendors' changes
clausetrail_list_workspace_changes
Every change published for the vendors you track, newest first, with where it stands for your team, the decision and who made it. Filter by status, vendor or date.
Ask: “What changed at our vendors this week that we haven't reviewed?”
Who uses a company
clausetrail_find_vendors_using
Which of your vendors name a given company as a subprocessor, or every AI provider your vendors use, with where each one processes data. On Team and Business.
Ask: “Which of our vendors send data to OpenAI?”
Shared subprocessors
clausetrail_list_dependencies
The companies your vendors rely on, most shared first. A company several of your vendors use is concentration risk. On Team and Business.
Ask: “Which subprocessors do most of our vendors depend on?”
Dependency graph
clausetrail_get_workspace_dependency_graph
Your vendors and the companies behind them as nodes and edges, with the purpose and locations each list gives. On Team and Business.
Ask: “Map our vendors to the AI providers behind them.”
A vendor's history
clausetrail_get_vendor_changes
The changes published for any vendor in the catalog: subprocessors added or removed, new locations, and changes to its DPA, policies, terms and AI terms, each with a severity and the date to object by.
Ask: “What has Notion changed in the last year?”
Subprocessor lists
clausetrail_get_subprocessors
A vendor's current subprocessor list as it publishes it: each name, purpose, location and data category, and the company behind the name.
Ask: “Which of Slack's subprocessors process data outside the EU?”
DPA terms
clausetrail_get_dpa_terms
What a vendor's DPA commits to: breach notice, notice before a new subprocessor, transfer mechanisms, deletion after the contract, liability and audit rights, each with the sentence behind it.
Ask: “How fast does HubSpot report a personal data breach?”
AI terms
clausetrail_get_ai_usage_terms
What a vendor's documents say about AI: whether it trains models on customer data, which model providers get it, the opt-out and how long AI data is kept, with quotes.
Ask: “Does Zendesk train AI models on our customer data?”
A vendor's dependencies
clausetrail_get_vendor_dependencies
The companies one vendor relies on, when each first and last appeared on its lists, and which are AI providers.
Ask: “Which AI providers does Intercom rely on?”
Vendor search
clausetrail_search_vendors
Search the catalog of vendors whose subprocessor lists, DPAs and policies ClauseTrail tracks, by name, domain or category.
Ask: “Which analytics vendors does ClauseTrail track?”

Safe to hand to ChatGPT

Read-only, workspace-scoped, revocable.

ChatGPT can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.

Questions, answered.

Can ChatGPT do vendor risk assessment?
On its own it answers from training data and whatever pages it finds. Connect ClauseTrail to Codex or the OpenAI API and it reads your vendors' current subprocessor lists, DPA terms, AI terms and every change ClauseTrail publishes for them, with the sentence each answer comes from.
Can I connect ClauseTrail to the ChatGPT app?
Not yet. Custom connectors in the ChatGPT app sign in with OAuth, and ClauseTrail's MCP server takes an API key today. Use Codex, which comes with paid ChatGPT plans, or the OpenAI API.
How do I connect Codex to ClauseTrail?
Create a key in ClauseTrail under Settings → API & MCP, then add a clausetrail entry to ~/.codex/config.toml that runs mcp-remote with https://clausetrail.com/mcp and the header Authorization: Bearer followed by your key. Restart Codex and ask about your vendors.
What vendor data can ChatGPT read through ClauseTrail?
Ten read-only tools: your vendors' changes with your team's decisions, which vendors use a company, shared subprocessors and the dependency graph (on Team and Business), and for any vendor in the catalog its change history, subprocessor list, DPA terms, AI terms and dependencies, plus vendor search.
Can ChatGPT change my ClauseTrail data?
No. Every ClauseTrail MCP tool is read-only and tells the client so. A key reads only your workspace's vendors and decisions, and you can revoke it at any time.
Does ClauseTrail have an API?
Yes. The same data answers as JSON from the REST API at https://clausetrail.com/v1, and the MCP server is at https://clausetrail.com/mcp. Both take an API key from Settings → API & MCP, on Pro, Team, and Business.
Is ClauseTrail affiliated with OpenAI?
No. ChatGPT and Codex are products of OpenAI. ClauseTrail is an independent vendor monitoring tool.

ChatGPT does the work. ClauseTrail brings the facts.

Add your vendors once. ClauseTrail checks their documents every day, and ChatGPT reads the result.

ChatGPT and Codex are products of OpenAI. ClauseTrail is not affiliated with or endorsed by OpenAI.