Skip to content
BYOK

BYOK for Anthropic Claude — your key, your billing, your control

Encrypted at rest with AES-256-GCM. Plus GitHub OAuth, SSO, and optional self-host on your AWS account.

At rest in Postgres
AES-256-GCM
Decrypt and discard
Per-request
Your billing, your invoices
Your Anthropic
Terraform on AWS
Self-host ready
The problem

Your security team is asking three questions you can't answer

Every AI coding rollout reaches the security review. These are the questions that stall it.

  • Where does our prompt data go?

    Which account do prompts run through, and who sees the invoices for that spend?

  • What happens if we switch vendors?

    If we move to another model provider, does our tooling, history and cost reporting come with us?

  • Where are the keys?

    Are they encrypted at rest with AES-256-GCM, how are they rotated, and which roles can use them?

01BYOK for Anthropic

Your Anthropic key, available today

Paste your Anthropic API key once in the admin settings. It is encrypted with AES-256-GCM before it ever touches disk, and every request runs through your own account, so the spend lands on your Anthropic billing, not ours.

  • Encrypted with AES-256-GCM before it is stored
  • Spend billed to your Anthropic account, never through us
  • A managed-key tier for teams without their own Anthropic account
02Multi-LLM cost tracking

One spend view across every provider

Bring your own key for Anthropic, OpenAI, Google Gemini or AWS Bedrock. Token costs from every provider are normalized into one spend view, so finance sees one number and engineering sees the breakdown by model.

  • Anthropic, OpenAI, Google Gemini and AWS Bedrock
  • Token costs normalized into a single spend view
  • One total for finance, a per-model breakdown for engineering
03GitHub OAuth and SSO

Sign-in and access that fit your stack

Connect GitHub in one click for commit and pull request data. Sign in with Google Workspace SSO restricted to your domain, or Okta and Azure AD on Enterprise, with four roles enforced on the server.

  • One-click GitHub OAuth for commit and PR data
  • Google Workspace SSO with domain restriction
  • Okta and Azure AD on Enterprise, four-role RBAC enforced server-side
04Self-host on AWS

Run the whole stack in your own AWS account

Terraform deploys the full CloudByte AI stack into your AWS account, isolated in your VPC. Use Bedrock for models, your own KMS for keys, and run fully air-gapped if you need to.

  • Terraform deploys everything into your AWS account
  • VPC-isolated, with an AWS Bedrock option
  • Your own KMS, and air-gapped deployments supported
Who it is for

Built for the people who sign off on AI

What BYOK changes for engineering leadership, and what it gives your auditors.

For CTOs and VPs of Engineering

No vendor lock-in, no billing middleman

  • The account stays yours, and AI spend is transparent to finance.
  • Swapping to OpenAI, Gemini or Bedrock is a configuration change, not a migration.
  • Self-host the whole stack on AWS when policy requires it.

For Security and Compliance

Controls your auditor will accept

  • AES-256-GCM at rest, TLS 1.2+ in transit, and every key use logged with actor and timestamp.
  • Rotation is one action in the admin UI, and the old key is retired immediately.
  • Per-seat hard caps, so no runaway script burns a month's budget.
FAQ

BYOK questions, answered

How keys are stored, billed and audited.

Bring your own key means your organization plugs in its own Anthropic API key. Every call bills to your Anthropic account, and CloudByte AI never proxies billing. The key is encrypted at rest and only decrypted for the request that needs it.

CloudByte AI normalizes token usage from Anthropic, OpenAI, Google Gemini and AWS Bedrock into a common cost-per-request metric, so spend from every provider adds up in one view and can be broken down by model, developer and project.

Keys are encrypted with AES-256-GCM and stored in your organization's Postgres row with a unique nonce per row. The encryption key lives in AWS Secrets Manager on the hosted service, or in your own KMS when you self-host. Keys are never logged.

Yes. Prompts reach Anthropic through your own account, inside your data boundary. Every key use, rotation and failed authentication is written to an audit log you can export for your auditors.

Yes, on the Enterprise plan. The stack is containerized and deployed with Terraform into your AWS account, and it can run air-gapped with AWS Bedrock inside your VPC.

Keep your key, your billing and your data.

Plug in your own Anthropic key and see every session, spend line and audit event in your own workspace.

  • Free for up to 5 developers
  • 10-minute setup
  • Your Anthropic key, your spend