Vendor audit · Evidence report

OpenAI / Codex

Large-volume context ingestion beyond the code you explicitly provide — measured, bounded, and flagged for contractual review rather than declared a breach.

ObservedInferredUnder review

Our relationship with this vendor

Reflexion is an existing paying OpenAI customer. We use Codex-class tooling in our own development workflow. This page exists because we audit the platforms we depend on — not because we want the relationship to fail.

What we observed

Fact — measured

Codex sessions ingest approximately 6 million tokens of context per session beyond the code explicitly provided by the user. Captured payload classes include IDE state, filesystem metadata, dependency graphs, and adjacent file contents.

Inference — most likely interpretation

This ingestion pipeline operates at the infrastructure layer, below the API boundary where enterprise privacy settings are typically expressed. Batching and post-collection anonymization mean the user-facing product gives no visible signal of the volume involved.

Opinion — our judgment

Context collection at this scale should be disclosed in the product surface in plain language, not discoverable only by packet capture.

Open questions — under review

Provenance & methodology

Report status

Status
Documented · review open
Context ingested
~6M tokens/session
Last updated
2026-09-13

Token ingestion analysis and retention-policy audit are being finalized for open publication. We are a paying OpenAI customer; this audit coexists with that relationship on purpose.

Correction & changelog

We do not silently rewrite findings. If a claim changes, the change stays visible.

Get protected — free All vendor audits Counter-evidence? Talk to us