Summary
Bridgit AI connects VDM directly to OpenAI using the OpenAI API key configured in VDM. Customer report content and AI requests are not routed through BridgeWorks servers for AI processing. Bridgit's Knowledge is saved locally on the user's workstation by default.
When you use an AI feature, VDM sends the request and supporting content to OpenAI so the model can respond. For analysis, that content can include actual report or dashboard data.
Note: Local Knowledge storage and direct communication with OpenAI describe two different parts of the workflow. Knowledge can be stored locally while relevant information from it is included in an OpenAI request.
How the Data Flows
- VDM connects to your data source. Your existing connection and permissions control access to the source data.
- VDM prepares the AI request. The feature being used determines which prompts, report content, files, and supporting context are included.
- VDM sends the request directly to OpenAI. API requests use encrypted HTTPS connections and the OpenAI API key configured in VDM.
- OpenAI returns the response to VDM. VDM displays the answer, analysis, or proposed report/query work within the application.
BridgeWorks does not operate an intermediary service that receives or stores this AI request content. This description covers the Bridgit AI processing path.
What Information Can Be Sent to OpenAI?
The information depends on the feature and its settings:
- Report and dashboard analysis: Content from the report or visualization being analyzed. Finished Reports can be provided as a PDF, and dashboards can be provided as an Excel export. These exports can contain the actual values and details in the report.
- Ask Bridgit and report building: Your request, relevant database structure, selected Knowledge, query text, and other context needed for the task.
- Chat attachments: Files or images supplied to the AI conversation.
- Voice features: Audio and conversation context used for transcription or the voice session.
- Optional context: Report layout or construction information when the applicable settings include it.
Bridgit Analysis should therefore be treated as sharing the submitted report content with OpenAI. Review that content before using AI with sensitive information; do not assume that names, identifiers, or other confidential values have been automatically removed.
Where Is Bridgit Knowledge Stored?
VDM saves connection-specific Knowledge and its search index as files in the configured Knowledge directory. By default, this directory is within the user's VDM application-data folder on the workstation. Organizations can configure another directory, so IT should verify the location and any backup or synchronization applied to it.
This local store contains information such as schema descriptions, terminology, instructions, examples, and saved query knowledge. It is not a BridgeWorks-hosted Knowledge repository.
Relevant Knowledge may be included in prompts sent to OpenAI. When OpenAI-based semantic search indexing is used, Knowledge text is also sent to OpenAI to generate embeddings, which are numerical representations used to find related information. The resulting index is saved locally.
See Bridgit AI Knowledge Editor Overview for information about managing Knowledge.
Does OpenAI Use the Data for Training?
OpenAI states that API data is not used to train or improve its models by default. Sharing data for that purpose requires an explicit opt-in. Bridgit uses the API, so review the policies and settings applicable to your organization's OpenAI API account.
Source: OpenAI API data controls.
Is Data Stored by OpenAI?
Retention depends on the API feature, request settings, and your organization's OpenAI controls. OpenAI documents default abuse-monitoring retention of up to 30 days, with exceptions. Some features also retain application state, and uploaded files can remain until deleted or expired.
VDM's API Logging setting can enable stored responses in supported chat workflows. Turning it off does not establish Zero Data Retention for every API feature. OpenAI's special retention controls require eligibility and approval and have feature-specific limitations.
Review the current OpenAI API data controls and retention documentation before assuming that a request or uploaded file is immediately deleted.
What Should IT Review Before Enabling Bridgit AI?
- Approved content: Identify which reports, files, and Knowledge are appropriate to send to OpenAI. Remove unnecessary sensitive fields from the submitted content.
- OpenAI account: Use an organization-approved API project and review its sharing and retention settings.
- VDM settings: Review API Logging, Include Layout, Web Tools, and Code Interpreter for the workflows being enabled.
- Local storage: Review access to the Knowledge directory, saved conversations, and diagnostic logs, including any organizational backups.
For setup and network prerequisites, see Using Bridgit Analysis.
OpenAI Security and Trust Resources
The OpenAI Trust Portal provides security and compliance information and access to supporting documentation for an IT or vendor review.
Direct link: https://trust.openai.com/
Article Summary
Bridgit AI communicates directly with OpenAI, and its AI request content does not pass through BridgeWorks servers. Knowledge is saved locally by default. The content supplied for AI processing can include report data and relevant Knowledge, and OpenAI's API policies and configured controls govern its handling and retention.
Comments
0 comments
Please sign in to leave a comment.