# How to roll out Claude or ChatGPT without leaking company data

> Does ChatGPT train on your data? Does Claude? A plan-by-plan guide to training defaults, retention, zero data retention, SSO, SCIM, domain claiming, audit logs and residency across ChatGPT Business, ChatGPT Enterprise, Claude Team and Claude Enterprise - plus the week-one checklist and the things you genuinely cannot control.

Canonical page: https://www.heybeagle.com/guides/how-to-roll-out-ai-without-leaking-company-data

Last reviewed: 2026-07-30

Roll out AI without the leak. Plan by plan, control by control.

The honest answer to "does it train on our data" is a table, not a sentence. It depends on the vendor, the plan, and whether anyone on your team has ever clicked thumbs up.

## The short answer

Neither vendor trains on business data by default. OpenAI states that it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API, and Anthropic says the same for Claude for Work and its API. Personal plans are the opposite: OpenAI uses content from its individual services for training unless the person turns it off, and Anthropic's privacy policy effective 8 July 2026 says it may train on inputs and outputs unless you opt out in account settings. That gap is the whole problem, because most company data that reaches an AI does not go through the account you approved. Verizon's 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% a year earlier, and that 67% of them reach AI services from non-corporate accounts. So the rollout is the control: verify your domain, turn on single sign-on, claim or block the personal accounts you can find, close the feedback exception that overrides an opt-out, set a retention window, and write down the things - browser extensions, personal webmail signups, data already in a training run - that you are simply not going to control.

## At a glance

- **Does it train on our data?**: Not on the business tiers. OpenAI does not train on ChatGPT Business, ChatGPT Enterprise or API content by default, and Anthropic does not train on Claude for Work or API content by default. Personal plans on both vendors are the reverse.
- **The exception nobody reads**: Feedback. On both vendors, submitting a thumbs up or down can put the whole conversation into training even when training is otherwise off, and Anthropic retains feedback data for up to five years. An owner can switch rating off org-wide on Claude.
- **Who has to approve it**: Whoever owns DNS. Domain verification is the prerequisite for single sign-on and for claiming personal accounts, and it is exclusive: once one organisation verifies a domain, no other can.
- **What single sign-on needs**: Less than people expect. SSO is available on ChatGPT Business and on Claude Team, so it is not gated behind an Enterprise contract. SCIM provisioning is the thing that is Enterprise-only on both.
- **How long data is kept**: Claude for Work keeps conversations indefinitely unless an Enterprise admin sets a custom window, with a 30-day minimum. Deleted chats on both vendors clear back-end storage within 30 days.
- **Time to set up**: A week for the controls that exist. Longer if you need zero data retention or non-US residency, because both require the vendor's prior approval rather than a toggle.
- **Biggest limitation**: You cannot claim an account you cannot see. Domain claiming only reaches accounts registered on a domain you own, so anyone who signed up with personal webmail stays invisible to you.

## Side by side

The rows are the controls a security review actually asks for. The columns are what you can buy. This is the table that decides whether you are on the right tier, and the honest headline is that the jump from a business plan to an enterprise one is mostly a jump in what you can export and prove.

| Capability | Personal accounts | ChatGPT Business | ChatGPT Enterprise | Claude Team | Claude Enterprise | Beagle |
| --- | --- | --- | --- | --- | --- | --- |
| Excluded from model training by default | No (Off by hand, per person) | Yes | Yes | Yes | Yes | Yes (Commercial API terms) |
| Single sign-on | No | Yes | Yes | Yes | Yes | Partly (Slack or Google identity) |
| SCIM provisioning | No | No (Manual only) | Yes | No (Just-in-time only) | Yes | No |
| Claim personal accounts on your domain | No | No (User-initiated) | Yes (Cancels their personal sub) | No (Blocks new ones only) | Yes (Fixed 30-day window) | No (Not applicable) |
| Audit log or compliance export | No | Partly (Admins can read chats) | Yes (Logs kept 30 days) | No | Yes (180 days, no content) | Partly (Activity feed) |
| Set your own retention window | No (30 days after you delete) | No | Yes (Admin-controlled) | No (Indefinite by default) | Yes (30-day minimum) | No |
| Zero data retention available | No | No | Yes (Sales approval needed) | No | Yes (Sales approval needed) | No |
| Data stored in the EU | No | No | Yes (New workspace only) | No | No (US only, or via a cloud) | No |

## What each one actually is

Four tiers and the thing you are actually replacing. Read these as a ladder: each rung buys a specific control, and knowing which rung you need is cheaper than buying the top one by reflex.

| Approach | What you get | Where it stops |
| --- | --- | --- |
| The personal accounts you already have (Already happening. Nobody approved it) | Free, Go, Plus, Pro and Max accounts your team signed up for themselves. They are the most capable consumer products in the world and people use them because they work. | Training is on unless each person turns it off, you have no visibility, no export and no way to revoke, and if someone used personal webmail you cannot even find the account. Verizon's 2026 report puts non-corporate account use at 67% of AI users on corporate devices. |
| ChatGPT Business (An afternoon. Self-serve) | The realistic starting tier. Business data is excluded from training by default, single sign-on is included, and OpenAI has been steadily moving admin features down into it. For most teams under a hundred people this is the right first purchase. | No SCIM, so provisioning and deprovisioning are manual. No custom roles, no compliance export, no zero data retention and no business associate agreement. Connectors are enabled by default here, which is the opposite of the Enterprise posture. One fact worth telling your team rather than hiding: on Business, workspace admins can view, export and delete members' conversations directly. |
| ChatGPT Enterprise (A sales cycle) | What you buy when you have to prove things rather than assert them. SCIM, custom roles, admin-controlled retention, a compliance platform that integrates with Purview, Netskope, Varonis and Zenity, data residency in a growing list of regions, and BAAs on request. | Residency has to be set up on a new workspace and cannot be retrofitted to an existing one, the compliance log platform itself only keeps 30 days so you still need somewhere to put the exports, and zero data retention is a negotiation rather than a setting. |
| Claude Team (An afternoon. Self-serve) | Anthropic's equivalent starting tier, from two seats up to a hundred and fifty. Commercial terms mean no training by default, single sign-on is included, and an owner can turn off chat rating org-wide, which closes the feedback exception properly rather than by asking people nicely. | Just-in-time provisioning only, so a user removed from your identity provider loses login but stays on the member list until someone removes them. No audit logs, no custom roles, no retention controls, and conversations are kept indefinitely by default. |
| Claude Enterprise (A sales cycle) | Adds SCIM, custom roles, audit logs, configurable retention with a 30-day floor, a compliance API with a large partner list, self-serve HIPAA enablement, and domain claiming that can find and migrate the personal accounts already on your domain. | Audit exports carry identifiers rather than content, and look back 180 days. There is no EU data residency on Anthropic's own platform - the only workspace geography is the US, and the European path runs through Bedrock, Vertex or Foundry instead. |
| An AI teammate instead of more seats (Minutes. Any Slack or Teams workspace) | A different answer to the same problem: rather than licensing a chat window for everyone and policing what they paste into it, put one accountable coworker in the channels where the work already happens. Beagle is one of these. It runs on commercial API terms, works under your existing OAuth grants, and holds every outbound action for a human's approval. | It is not a replacement for a chat subscription, and people will still want one. There is no SCIM, no configurable retention window and no zero-data-retention agreement to sign. Treat it as the thing that removes the reason to paste, not as the thing that satisfies your auditor. |

## Step by step

A week's work, in the order that stops you undoing something. Two of these steps are one-way doors, and they are both in the first three days, so read before you click.

1. **Verify your domain, from the organisation you mean to keep** - Domain verification is the prerequisite for single sign-on and for claiming accounts, and on ChatGPT it is exclusive: once one organisation has verified a domain, no other organisation can, which can block a sibling org on the same email domain from setting up SSO at all. Decide which workspace is the real one before you verify, not after. One-way door: Exclusive per organisation, and not casually undone
2. **Turn on single sign-on, which is cheaper than you think** - SSO is available on ChatGPT Business and on Claude Team, not only on the enterprise tiers, so there is no reason to run an unauthenticated pilot while you wait for procurement. Note the gap that remains: SCIM provisioning is Enterprise-only on both vendors, so on the lower tiers deprovisioning is a manual step somebody has to own. Note: Claude Team gets just-in-time provisioning, not SCIM
3. **Deal with the personal accounts that already exist** - On Claude Enterprise, domain claiming finds existing Free, Pro and Max accounts on a verified domain and migrates them. Budget for it: the migration window is a fixed 30 days, it cannot be customised, and accounts that do not migrate are deactivated with subscriptions cancelled and prorated. On ChatGPT Enterprise an invited user on a verified domain is prompted to migrate and their personal paid subscription is cancelled as part of it. On the business tiers you can ask, but you cannot enforce. Communicate first: The window is 30 days and it is not adjustable
4. **Close the feedback exception** - This is the control most rollouts miss. Both vendors carve feedback out of the no-training default: a thumbs up or down can put the entire associated conversation into training even for an opted-out user, and Anthropic retains that data for up to five years. On Claude an owner can turn rating off for the whole organisation. On ChatGPT there is no equivalent switch, so it has to be a briefing. Where: Claude: Organization settings, Data and privacy, Rate chats
5. **Audit connectors and sharing, because the defaults differ** - Apps and connectors are enabled by default on ChatGPT Business but disabled by default on Enterprise and Edu, which surprises teams who assume the cheaper tier is the more locked-down one. On Claude, public projects are enabled by default on both Team and Enterprise and can be disabled org-wide. Do this before the first sensitive document goes in, not after.
6. **Set retention deliberately rather than by default** - Claude for Work keeps conversations indefinitely unless an Enterprise admin sets a custom period, with a 30-day floor. Be careful the first time: saving a shorter window deletes everything outside it immediately and irrecoverably. On ChatGPT Enterprise and Edu, retention duration is admin-controlled and deleted conversations clear within 30 days. Irreversible: Shortening the window deletes out-of-window data on save
7. **Send the logs somewhere you actually keep them** - Both compliance surfaces are Enterprise-tier, and both are shorter-lived than your retention policy probably is. OpenAI's compliance log platform keeps 30 days. Claude's audit log export looks back 180 days, carries identifiers rather than chat content, and arrives as an emailed CSV link valid for 24 hours. Wire them into your existing tooling and archive on your side.
8. **Write down what you are not controlling** - A control list is only honest if it has a second half. You cannot see accounts registered on personal webmail. You cannot pull data back out of a model that has already trained on it. You cannot opt out of safety retention. And you cannot rely on approval prompts at scale - Anthropic measured 93% blanket approval of Claude Code permission prompts before it added operating-system sandboxing.

## What trips people up

The specific things that are wrong in most internal AI policies right now, including one that was true a year ago and is not any more.

- **The court order everyone still quotes was terminated** - The May 2025 preservation order in the New York Times litigation, which required OpenAI to preserve output log data that would otherwise have been deleted, was terminated on a going-forward basis as of 26 September 2025 by a stipulation entered on 9 October 2025. It is not a live reason to avoid ChatGPT, and repeating it in the present tense will cost you credibility with anyone who checked. Two caveats keep it from being a clean win: data already segregated before that date is still preserved, though log data from the EEA, Switzerland and the UK is carved out, and going-forward preservation continues for accounts associated with roughly ninety named publisher domains.
- **Feedback beats your opt-out** - You can set every training toggle correctly and still put a conversation into a training set by clicking thumbs up. Both vendors say so plainly. It is the single highest-yield thing to fix, because it is one switch on Claude and one sentence in your onboarding note everywhere else.
- **Business is not a cheaper Enterprise, it is a different shape** - The gap between the tiers is not capability, it is provability. Business gives you no SCIM, no custom roles and no compliance export on either vendor, and on ChatGPT it also turns connectors on by default rather than off. If your security review asks for evidence rather than assurances, the exports are what you are buying.
- **The browser is the hole nobody budgeted for** - Verizon's 2026 report found the average company had more than 15% of users running unauthorised AI extensions. The risk is structural, not hypothetical: researchers have shown that any extension with page access can reach the DOM of a chat tool to inject prompts and read the replies, and in December 2025 a flaw in Anthropic's own Chrome extension allowed any website to inject prompts silently, fixed in version 1.0.41 in January 2026. None of this appears in your AI vendor's audit log, because none of it happens on their side.
- **A shared link is a public object** - In July 2026 shared Claude conversations and artifacts were found indexed by Google. Anthropic's position is that it does not give search engines chat directories or sitemaps, and that sharing a conversation makes it publicly accessible content that third parties may archive - which is correct, and also exactly the problem. OpenAI removed its own discoverable-sharing option in July 2025 after indexed chats surfaced in search results. On both vendors, Team and Enterprise sharing is confined to the organisation. On personal plans it is not.
- **Approval prompts stop being a control at scale** - Every agentic rollout leans on human-in-the-loop as the answer to blast radius, and it degrades. Anthropic's own engineering writeup reports 93% blanket approval of permission prompts before sandboxing, and that experienced users auto-approve about twice as often as new ones. Design for the assumption that the prompt will be accepted, and put the real limit somewhere the human is not.
- **There is no EU data residency on Anthropic's own platform** - If a European residency requirement is on your checklist, check this one early rather than late. Anthropic's only workspace geography is the US and it cannot be changed after creation, so the European path runs through Bedrock, Vertex or Azure Foundry instead. OpenAI does offer residency in Europe and a number of other regions, but it has to be configured on a new workspace and cannot be retrofitted to the one you have been using.

Most company data does not leak through the AI you approved. It leaves through the one somebody signed up for on a Tuesday, on their own card, in a browser tab you cannot see.

## Or skip the build

The durable fix for shadow AI is not a stricter policy, it is a sanctioned thing that is better than the unsanctioned one. Beagle is built for that shape: it lives where the work already is, so there is less reason to paste anything anywhere.

- **Nothing to paste in the first place** - Beagle reads the CRM record, the thread and the ticket directly, so the context never has to be copied out of a system of record into a chat window on someone's personal account.
- **It runs on your existing grants, not a new pool of data** - Every connection is your own OAuth, so Beagle reaches exactly what you reach and nothing more. Tools can be switched off one at a time when you want a narrower blast radius on a particular connection.
- **Every outbound action waits for a human** - Drafts, replies, updates and record changes are all held for approval. The design assumption is the one Anthropic's own data supports: that the person will click yes, so the limit has to be somewhere other than the click.
- **One accountable account, not forty invisible ones** - Work happens in the channel where the team already is, which means it is visible to the team by default. That is a weaker guarantee than an audit log and a stronger one than hoping nobody opened a private tab.

## In your stack

Teams here usually connect: Slack, Gmail, Drive, Notion, HubSpot, Linear. Beagle connects to ~3,200 tools in total - see https://www.heybeagle.com/integrations.

## FAQ

**Does ChatGPT train on my company's data?**

Not on the business products. OpenAI states that by default it does not train on any inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API. Individual plans are the opposite: content from OpenAI's services for individuals may be used to train models unless the person switches it off under Settings, Data controls, Improve the model for everyone. Two exceptions survive the toggle on every plan - submitting feedback on a conversation can put the whole conversation into training, and support conversations may be used to improve models if training is enabled.

**Does Claude train on our data?**

Not on the commercial products. Anthropic states that by default it will not use inputs or outputs from Claude for Work, the API or Claude Gov to train models. Consumer plans are different: the privacy policy effective 8 July 2026 says Anthropic may use inputs and outputs for training unless you opt out in account settings, and users who allow it move from 30-day retention to five-year retention. The exception on commercial plans is feedback, which an organisation owner can disable by turning off chat rating.

**Is the New York Times court order still forcing OpenAI to keep our deleted chats?**

No, not on a going-forward basis. The May 2025 preservation order was terminated as of 26 September 2025 by a stipulation entered on 9 October 2025. Output log data OpenAI had already segregated before that date is still preserved, with a carve-out for requests originating in the EEA, Switzerland and the UK, and preservation continues going forward for accounts associated with roughly ninety named news-publisher domains. If your AI policy still cites the order as a current reason to avoid ChatGPT, it needs updating.

**What is the difference between ChatGPT Business and Enterprise for security?**

Both exclude your data from training by default and both support single sign-on. Enterprise adds the things a formal security review asks for: SCIM provisioning, custom roles, admin-controlled retention, the compliance platform and its integrations with tools like Purview and Netskope, data residency, business associate agreements and zero data retention on request. There is also a default worth knowing: connectors are enabled by default on Business and disabled by default on Enterprise.

**Can we get EU data residency for Claude or ChatGPT?**

For ChatGPT, yes. OpenAI offers data residency in Europe and several other regions for Enterprise, Edu and eligible API customers, with the caveat that it must be configured on a new workspace rather than added to an existing one, and that inference residency is a narrower list than storage residency. For Claude, not directly. The only workspace geography on Anthropic's own platform is the US and it cannot be changed after creation, so European residency for Claude runs through AWS Bedrock, Google Cloud Vertex or Microsoft Foundry regional endpoints instead.

**What can we not control, however much we spend?**

Four things, and a policy that pretends otherwise will be ignored. You cannot find or claim accounts your staff registered with personal webmail, because domain claiming only reaches domains you own. You cannot retract data from a model that has already been trained on it. You cannot opt out of safety retention: both vendors keep policy-violation material and classifier results well beyond their normal windows, and Anthropic does so even under a zero-data-retention agreement. And you cannot treat an approval prompt as a hard control once people are used to it.

## Read next

- [How Beagle handles data](https://www.heybeagle.com/security): Scopes, approvals and what we keep
- [Claude and MCP](https://www.heybeagle.com/guides/how-to-connect-claude-to-your-tools-with-mcp): The connector side of the same question
- [Beagle for larger teams](https://www.heybeagle.com/enterprise): What the security review usually asks

Try Beagle free: https://www.heybeagle.com/signup (1,000 credits, no credit card).
