BYOK · Key handling

Your key is the one thing
we never touch.

It's the question every serious buyer asks first: what happens to our provider API key? Here is the honest, end-to-end answer. You bring your own key, it's sealed in an encrypted per-tenant vault, the broker injects it for exactly one call after a policy check, and it never enters the agent sandbox — which has no route to the internet anyway. You don't have to take our word for it: every call is signed, and you re-verify the proof yourself.

The lifecycle of your key

Four steps, and only one of them
ever holds the secret.

Follow your key from the moment you add it to the moment a call is made. Each step is enforced below the agent, so the agent can't reason its way to your secret.

01

You bring your own key BYOK

Use your own provider account — any major model provider, or any OpenAI-compatible endpoint. We are not a usage middleman: your provider bills you directly for tokens, and PerimeterOne never marks up your usage. The key is yours; you can rotate or revoke it at the provider whenever you want.

02

It's sealed in an encrypted vault PER-TENANT · NEVER LOGGED

The moment you add it, the key is encrypted at rest in a per-tenant vault scoped to your account alone. It's never written to a log, never echoed back to a screen, and never transmitted for our own use. We can't read it for our benefit, and neither can another tenant.

03

The broker injects it at call time AFTER A POLICY CHECK

One broker process is the only thing on the box that can reach a provider. When the agent needs a model, the broker checks the call against policy — a known model, the per-run and per-tenant budget cap not exceeded, the kill-switch clear — and only then attaches your key for that single call. No policy pass, no call.

04

It is never inside the sandbox NO ROUTE OUT

The agent runs in its own locked container on an internal-only network with no path to the internet. Your key never enters that container — and even if it somehow did, there is no route for it to leave. Containment first; the key simply has nowhere to go.

We are not a usage middleman. BYOK, zero markup — your provider bills you directly, and you can re-verify every call yourself.
— The PerimeterOne premise
Why this holds

Three commitments, none of them
asking for blind faith.

The same controls that protect your key produce the evidence that proves they ran. Trust the proof, not the promise.

Encrypted at rest

Your key lives in a per-tenant encrypted vault — never in plaintext logs, never in a screenshot, never shared across accounts. Stored to be used by the broker, not read by us.

VAULT · SEALED

Sole-egress injection

One broker is the only door out. It attaches your key for exactly one policy-checked call, then it's gone — the secret never crosses into the agent's container.

ONE DOOR · ONE CALL

You verify, not us

Every call is Ed25519-signed and hash-chained. Export the run and re-verify each event offline on your own machine with our standalone verifier. Proof you hold, not a claim you accept.

TAMPER-EVIDENT

Hand an agent real power
without handing over your key.

Add your provider key, point an agent at a real task, and watch it work behind the broker — then export the proof and re-verify it yourself. Solo $29 · Team $544 · Business $1,779.