Integration overview

    The Wiz OpenAI integration extends the visibility and security workflows teams already have across their cloud infrastructure to their OpenAI environments. By mapping OpenAI resources onto the Security Graph, security teams can identify sensitive data in AI training sets, detect misconfigurations and policy violations, and see how AI resources connect to broader cloud risk. As a result, organizations can govern their AI pipelines with the same rigor as the rest of their environment.

    Market Challenge

    AI adoption is accelerating across organizations, teams are building with OpenAI's APIs, deploying assistants, and fine-tuning models on proprietary data across multiple projects and organizations. As AI becomes a core part of the technology stack, security teams need to extend the same visibility, policies, and workflows they have across their cloud infrastructure to their AI environments - ensuring AI resources are governed with the same consistency as everything else.

    Benefits of the Integration

    • AI Bill of Materials (AI-BOM): The OpenAI connector maps models, assistants, fine-tuning jobs, vector stores, users, and permissions onto the Wiz Security Graph — building a comprehensive inventory of your OpenAI environment. Security teams get a single view of what's deployed, who has access, and how it's configured across their OpenAI organization or specific OpenAI project.

    • Sensitive Data Visibility: Identify sensitive information including personal data, credentials, and confidential business content, across OpenAI training sets, vector stores, and files attached to assistants. Teams can see where sensitive data is being used and how it connects to models and applications across the environment.

    • Configuration and Access Guardrails: Wiz continuously assesses OpenAI configurations and user permissions to identify overly broad access, missing controls, and configuration risks at the organization level. Security and development teams can establish appropriate guardrails together using existing workflows. 

    • Contextual Risk and Attack Path Analysis: Connect OpenAI resources to the broader cloud environment to understand relationships between AI applications, storage, databases, identities, and network access. With this context, teams can prioritize toxic combinations of risk based on exploitability.

    • Threat Visibility: Monitor activity across cloud workloads and OpenAI services to identify unauthorized usage, anomalous behavior, and potential threats to AI data pipelines. Security teams gain visibility into how AI is being used across the environment and where additional investigation may be needed.  


    Better Together

    OpenAI provides the models, APIs, and platform teams use to build with AI across the organization. Wiz brings those OpenAI resources into the same security context as the rest of the cloud, so organizations can understand, govern, and protect their AI environments without creating separate security workflows.

    Together, OpenAI and Wiz help security teams maintain a consistent security posture across cloud and AI, with the context they need to prioritize risk while development teams keep building.

    Use case overview

    Extending Cloud Security to OpenAI Environments:

    Challenge

    An enterprise has multiple teams building with OpenAI across several organizations and projects. Each team is deploying assistants, fine-tuning models on proprietary data, and connecting to different data sources. Security has visibility across the cloud environment, but OpenAI resources sit outside that view, making it difficult to apply the same governance, assess configurations, and understand how AI resources connect to broader cloud risk.

    Solution

    The Wiz integration connects to OpenAI at both the organization and project level, bringing OpenAI resources into the Security Graph alongside the broader cloud environment. Security teams gain a centralized inventory of OpenAI models, assistants, fine-tuning jobs, and permissions. Wiz scans training data for sensitive information, evaluates configurations against policy, and correlates OpenAI resources with the broader cloud to surface attack paths and prioritize risk.

    Security teams can govern OpenAI through the same workflows they use across their cloud environment, while development teams keep building.

    cloud security provider?

    Become a Wiz Technology Partner

    WIN with us Already a partner?Log in

    Get a personalized demo

    Ready to see Wiz in action?

    "Best User Experience I have ever seen, provides full visibility to cloud workloads."
    David EstlickCISO
    "Wiz provides a single pane of glass to see what is going on in our cloud environments."
    Adam FletcherChief Security Officer
    "We know that if Wiz identifies something as critical, it actually is."
    Greg PoniatowskiHead of Threat and Vulnerability Management