Key facts
| White-label option | Your brand, domain and colours on the dashboard; resale under your SKU |
| API layer | OpenAI-compatible /v1 endpoints with 30+ models behind one key |
| Tenant isolation | One project and scoped key per tenant, held server-side |
| Metering | Per-request logs and per-key usage for quotas and billing |
| Residency | Region pinning per workspace plus VPC/on-prem tiers |
| Governance | SSO/SCIM, RBAC, PII modes and audit export for enterprise customers |
| Contractual frame | Resale and branding terms live in the platform terms at /legal/terms |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Sell outcomes and quotas, not tokens — that is where SaaS margin lives.
- Hold the keys yourself; customers should never see provider credentials.
- Isolate tenants with projects, scoped keys and per-tenant logging.
- Pass through residency options your customers demand, then verify them.
- Read the resale, branding and support terms before publishing pricing.
How it works, step by step
- Define the packaged feature and the plan tiers customers will buy.
- Set the tenancy model: one project and scoped key per customer.
- Build metering from platform logs and map usage to quotas and pricing.
- Apply your brand to customer-facing surfaces and keep provider names out of errors.
- Define support boundaries: what you handle and what escalates upstream.
- Pass through residency and compliance options, with evidence for enterprise buyers.
- Review the resale and branding terms, then launch with a pilot cohort.
Try it yourself
Open the private LLM cost estimator →
What to package and how to price it
Customers buy outcomes: drafts generated, tickets resolved, documents summarised, searches answered. Package around those units and around seats or usage tiers, not around tokens — token-based pricing exposes your cost structure and invites comparison with raw API pricing. Because Plugsky self-serve plans are flat-rate with fair-use usage, your margin comes from the value you add: workflow, data connections, guardrails and support. Design three tiers with clear limits, and keep an internal cost model that tracks platform plan plus engineering time, not per-call token arithmetic.
Tenancy, keys and isolation
- One project per customer: scoped keys held server-side by your gateway, never exposed to end users.
- Per-tenant rates and caps: rate limits and spend caps stop one customer's runaway job from affecting others.
- Logging and metering: per-request logs with key ID give you billing data and incident forensics.
- Data boundaries: pin a region per tenant where their rules require it, and separate retrieval collections per tenant.
- Rotation: because you hold the keys, rotation is invisible to customers — make it routine.
Compliance pass-through for enterprise deals
Your enterprise customers will ask questions their procurement teams generated: where does data live, who can access it, is it used for training, how is it deleted, what happens on termination. You need credible answers, passed through accurately from your provider and your own controls. Offer region pinning where it satisfies the requirement, and escalate to VPC, on-prem or air-gapped options for stricter buyers. State certification status exactly as it is — Plugsky documents SOC 2 Type II and ISO 27001 as readiness in progress rather than completed — and keep the evidence pack: residency map, subprocessor locations, audit samples and the signed terms at /legal/terms and /legal/sla.
Support, risk and the honest limits
Define the support boundary in writing: your team handles product issues, configuration and customer data questions; platform incidents escalate upstream with a documented path and the status page as the source of truth. Build a degraded-mode experience so an upstream incident is a visible, graceful failure rather than a silent one. Manage concentration risk by keeping the OpenAI-compatible core portable and knowing which workloads could move first. And avoid over-claiming: do not promise endpoints that are not live, do not imply certifications you do not hold, and do not pass through contractual commitments without legal review. The reselling business is built on trust in exactly those details.
Honest comparison
| Dimension | White-label on Plugsky | Direct from each model vendor | Self-hosted models |
|---|---|---|---|
| Branding | Your brand, domain and SKU | Vendor branding | Fully yours |
| Model access | 30+ models, one API and invoice | Multiple vendor contracts | Whatever you host |
| Infrastructure | Managed; no GPUs | Managed per vendor | GPUs, ops and upgrades |
| Tenant controls | Scoped keys, per-key metering | Per-vendor key models | You build everything |
| Residency options | Region pinning plus private tiers | Vendor regions | Your facilities |
| Compliance evidence | Platform controls plus your own | Varies by vendor | Your own programme |
Frequently asked questions
Can I put my own brand on the AI?
Yes. The white-label deployment puts your brand, domain and colours on the dashboard so you can resell under your own SKU. Review the branding and resale terms at /legal/terms before launch.
How do I charge customers for AI usage?
Package outcomes or usage quotas rather than raw tokens. Meter per request with platform logs and per-key usage, then map usage to your plan limits and pricing.
Who holds the API keys?
You do. Hold one scoped key per tenant server-side in your gateway, never in client code. That keeps rotation invisible to customers and revocation instant.
How do I keep tenants isolated?
Use one project and scoped key per customer, per-tenant rate limits and spend caps, separate retrieval collections, and per-key logging for billing and incident forensics.
What compliance questions will buyers ask?
Residency, access, training use, retention, deletion and termination. Answer from evidence: region configuration, subprocessor locations, audit samples and the terms at /legal/terms and /legal/sla.
Can customers choose where their data lives?
Region pinning is available per workspace, and enterprise deployments extend to VPC, on-prem and air-gapped. Offer the tier that satisfies the customer, then verify the configuration.
What happens when the platform has an incident?
Failover routes around unhealthy upstreams, and the status page shows platform incidents. Define the escalation path and build a graceful degraded mode into your product.
Should I disclose which models I use?
That is a product decision, but never imply capabilities you do not have. If you claim a certification or endpoint, it must be true and verifiable; otherwise disclose the status accurately.