Weekly vendor brief
What your vendors changed this week, and what to review.
“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”
Guide · ChatGPT
Ask ChatGPT about a vendor's subprocessors and it answers from what it read months ago. Connect ClauseTrail and OpenAI's agent reads the vendor's current list, DPA terms and AI terms instead, with the sentence each answer comes from. Here is how to set it up with Codex, which comes with your ChatGPT plan, or with the OpenAI API.
Add your vendors to ClauseTrail and create an API key. Then add ClauseTrail to Codex, OpenAI's agent included with paid ChatGPT plans, or to the OpenAI API's MCP tool. Ask about your vendors in plain words and it answers from their own documents. Connectors inside the ChatGPT app need OAuth sign-in, which ClauseTrail does not support yet.
Which of our vendors started sending data to an AI provider this quarter?
Codex · used ClauseTrail
Two. Northwind CRM added Anthropic, PBC for email drafting on 12 August, with 30 days to object. Lumen Analytics now names OpenAI for its product assistant, processing in the United States. Neither's AI terms say it trains on customer data.
Answered from ClauseTrail, not model memory
Illustrative thread with fictional vendors.
Step by step
Sign up and add the vendors that handle your customers' data, or import them from a CSV. ClauseTrail checks each one's subprocessor list, DPA, privacy policy, terms and AI terms every day and keeps every version, so ChatGPT can answer what changed and when.
In ClauseTrail, open Settings → API & MCP and create a key, on Pro, Team, and Business. It is shown once, it can only read, and you can revoke it at any time.
Codex is OpenAI's agent and signs in with your ChatGPT account. Add ClauseTrail to its config file. You need Node.js installed for the npx bridge.
Codex (~/.codex/config.toml)
[mcp_servers.clausetrail]
command = "npx"
args = ["-y", "mcp-remote",
"https://clausetrail.com/mcp",
"--header", "Authorization: Bearer YOUR_KEY"]
Connectors inside the ChatGPT app authenticate with OAuth sign-in, which ClauseTrail does not offer yet, so use Codex or the API for now.
Ask what you want to know. Codex picks the right ClauseTrail tool and answers from tracked data, with dates, severities and quotes.
“Use ClauseTrail to list the changes our vendors made this month that we haven't reviewed, and tell me which one to look at first.”
Ask for the format you need: a vendor assessment, an objection email to the vendor, a note for the DPO or a table for the auditor. The facts come from ClauseTrail and ChatGPT's writing does the rest.
“Draft an email objecting to Northwind CRM's new subprocessor, citing the notice period in its DPA.”
Add ClauseTrail as a remote MCP tool in the OpenAI Responses API. Your own assistant, Slack bot or procurement tool can then answer vendor questions from the same data.
OpenAI Responses API tool
{ "type": "mcp",
"server_label": "clausetrail",
"server_url": "https://clausetrail.com/mcp",
"authorization": "YOUR_KEY",
"require_approval": "never" }
Workflows to copy
What your vendors changed this week, and what to review.
“List the vendor changes in ClauseTrail we haven't reviewed, highest severity first, as a five-bullet brief with the date to object by.”
The first pass of a vendor review, from the vendor's own documents.
“We're evaluating Notion. From ClauseTrail, list its subprocessors outside the EU, its breach notice and subprocessor notice, and whether it trains AI on customer data, with quotes.”
Line up the terms that matter across vendors in one table.
“Compare breach notification, subprocessor notice and deletion after termination across Slack, HubSpot and Notion from ClauseTrail, as a table.”
Answer the board's question: which vendors send our data to AI?
“Which of our vendors send data to an AI provider, which providers, and do their AI terms say they train on customer data?”
See which companies sit behind many of your vendors at once.
“List the subprocessors most of our vendors share in ClauseTrail, and what would be affected if the top one had an incident.”
The record an auditor asks for, without a spreadsheet.
“List every vendor change since January 1 in ClauseTrail with our decision and who made it, as a table.”
Available over MCP
10 read-only tools on ClauseTrail's MCP server. ChatGPT chooses the right one from your question, so you never call them by name.
Safe to hand to ChatGPT
ChatGPT can read ClauseTrail data, never change it. Every tool is read-only and tells the client so. A key reads only your own workspace's vendors and decisions. Keys are stored hashed, shown once, and revoked instantly from Settings → API & MCP. The same data answers as JSON in the API reference.
Add your vendors once. ClauseTrail checks their documents every day, and ChatGPT reads the result.
ChatGPT and Codex are products of OpenAI. ClauseTrail is not affiliated with or endorsed by OpenAI.