Key facts
| Key custody | Customer-managed keys via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM |
| Encryption | AES-256 at rest with envelope encryption and per-region KMS; TLS 1.3 in transit |
| Revocation | Revoking the key cuts access to protected data — a live control you operate |
| Deployment | Cloud, your VPC, on-prem and air-gapped tiers all support customer key custody |
| Access control | SSO (SAML 2.0 or OIDC), SCIM provisioning and RBAC at workspace, role and resource level |
| Audit | Key lifecycle and access events exportable to SIEM (Splunk, Sentinel, QRadar, Datadog) |
| Start cost | Free plan with plugsky-micro and plugsky-lite, no card required |
| Adoption path | Customer key custody when a deal requires it, without code changes |
TL;DR
- Your KMS or HSM holds the master key; revocation becomes a live control you operate.
- Envelope encryption with AES-256 at rest and TLS 1.3 in transit keeps rotation cheap.
- Start with scoped keys and standard encryption; adopt BYOK when a deal requires it.
- Rehearse rotation and revocation in staging as soon as procurement begins.
- Start free with plugsky-micro and plugsky-lite; a 14-day full-access trial covers larger models.
How it works, step by step
- Decide which stores fall under customer-managed keys and name the owner of the key lifecycle.
- Create the key in your KMS or HSM and reference it from the Plugsky workspace.
- Rehearse rotation and revocation in staging before any production data is protected.
- Build on the free plan with plugsky-micro and plugsky-lite and no card.
- Record which stores would need customer keys when the first enterprise deal lands.
- Test rotation and revocation in staging before promising custody in a contract.
Try it yourself
Open the private LLM deployment estimator →
BYOK for startups: what changes
Startups rarely need BYOK on day one; they need to ship. But the first enterprise deal usually arrives with a security questionnaire, and key custody questions appear on page two. The pragmatic path is to start with the standard encryption model and adopt customer-managed keys when a contract requires it.
BYOK means you supply and control the keys that protect your data — through a cloud KMS such as AWS KMS or Azure Key Vault, HashiCorp Vault, or an on-prem HSM — while Plugsky performs cryptographic operations with envelope encryption: a master key you own wraps the data keys that protect each store, so rotating or revoking a small key changes access without touching the corpus. AES-256 protects data at rest with per-region KMS, TLS 1.3 protects it in transit, and key permissions are separated from platform administration.
Architecture and controls
Use scoped API keys per environment and SSO when the team grows, and rely on the standard model — AES-256 at rest with per-region KMS — until a buyer asks for more. When they do, BYOK through AWS KMS, Azure Key Vault, HashiCorp Vault or HSM is available without changing application code.
Integration pattern and rollout
Begin on the free plan with plugsky-micro and plugsky-lite and no card so you can build and demo before procurement exists. Rehearse rotation and revocation in staging as soon as a deal enters the pipeline, and keep the runbook in your security documentation.
Integrate custody as configuration, not application code. A workspace references the key provider, your services keep using the same OpenAI-compatible endpoints, and the security team owns the key lifecycle: creation, rotation, revocation and evidence. Because the key hierarchy is external to the application, a change of custody does not change prompts, evaluations or SDK usage.
Limits, evidence and cost
Adopting BYOK too early adds operational work you may not be ready for: key availability becomes your availability. Wait for a concrete requirement, then adopt it as a documented control with a named owner.
Pricing stays flat-rate on self-serve plans — see the live pricing page for current tiers — so key custody does not introduce per-operation billing. Start on the free plan with plugsky-micro and plugsky-lite and no card, then use the 14-day full-access trial to evaluate larger models before procurement.
Honest comparison
| Concern | Plugsky BYOK | Vendor-managed keys | Building in-house |
|---|---|---|---|
| Key custody | Your KMS or HSM; keys separated from platform administration | Vendor KMS and shared control plane | You build and run the whole stack |
| Revocation | Revoke the key and protected access stops | Usually a vendor support process | You own the runbook |
| Evidence | Key lifecycle and access events exportable to SIEM | Vendor portal logs | Custom logging pipeline |
| Operational load | You own key availability, rotation and backups | Vendor owns the lifecycle | You own everything |
| Time to control | Configuration on supported tiers | Available immediately | Quarters of engineering |
| Time to control | Adopt when a deal requires it; no code change | Managed for you | Premature operational load |
Frequently asked questions
What does BYOK actually change?
You supply and control the master key through a KMS or HSM while Plugsky performs cryptographic operations with envelope encryption. Revoking your key stops access to protected data, and key operations stay auditable.
Who is responsible when a key is unavailable?
You are. Key availability becomes your availability, so plan KMS or HSM redundancy, break-glass procedures and incident response before go-live.
Does BYOK replace certification or a DPA?
No. It is one technical control. Compliance posture — SOC 2 Type II and ISO 27001 readiness in progress — and contractual terms such as the DPA must be reviewed separately.
Do we need BYOK before we have enterprise customers?
No. Start with the standard encryption model and scoped keys, then adopt customer-managed keys when a contract requires them.
How long does adoption take?
On supported tiers it is configuration rather than a rewrite, because the API stays OpenAI-compatible. The real work is the runbook and rotation testing.
What should we tell a buyer asking about keys?
Describe what you have today, the KMS and HSM options available, and the path to customer custody. Evidence beats promises in a review.