Bring Your Own Key (BYOK)
Configure custom AI provider keys, fallback hierarchies, and private self-hosted inference endpoints.
ScanDrix is model-agnostic. While managed plans include optimized multi-model inference out of the box, teams can supply their own API keys (BYOK) or route inference to private, on-premise models.
Why use BYOK?
- Direct Provider Billing: Leverage existing enterprise commitments or volume discounts with Anthropic, OpenAI, Google Cloud, or AWS.
- Data Sovereignty: Ensure all inference requests use your existing zero-data-retention agreements directly with model vendors.
- Model Choice: Select specialized models per review stage (e.g. fast models for syntax linting, reasoning models for taint analysis).
- Air-Gapped Privacy: Route requests to local vLLM or Ollama instances inside your private VPC with zero public internet egress.
Supported model providers
Claude 3.5 Sonnet, Claude 3.5 Haiku, Claude 3 Opus via direct API or AWS Bedrock.
GPT-4o, GPT-4o-mini, o1, and o3-mini via OpenAI API or Azure OpenAI Service.
Gemini 1.5 Pro and Gemini 1.5 Flash via Google AI Studio or Google Cloud Vertex AI.
DeepSeek R1, Llama 3.3, and Qwen 2.5 hosted via vLLM, Ollama, or TGI.
Configuring BYOK in the dashboard
Navigate to AI Providers
In the ScanDrix dashboard, go to Settings → AI Providers.
Add your credentials
Select your target provider (e.g. Anthropic, OpenAI, or Custom OpenAI-Compatible) and paste your API key.
Configure model routing
Assign models to specific review pipelines:
- Taint & Security Analysis: High-reasoning model (e.g.
claude-3-5-sonnet-latestorgpt-4o). - Fast Linter & Style Rules: Low-latency model (e.g.
claude-3-5-haiku-latestorgpt-4o-mini).
Test and verify connection
Click Test Connection to send a synthetic health ping and verify quota availability before activating the provider.
Private VPC & local inference (Ollama / vLLM)
For air-gapped environments, ScanDrix supports any OpenAI-compatible HTTP completion endpoint:
# .scandrix.yaml or dashboard provider config
ai:
provider: custom_openai
endpoint: "http://vllm-service.internal.vpc:8000/v1"
model: "deepseek-ai/DeepSeek-R1-Distill-Qwen-32B"
api_key: "env:VLLM_INTERNAL_KEY"
max_tokens: 4096
temperature: 0.1
Security & key rotation
- All provider keys are encrypted at rest using AES-256-GCM with tenant-isolated envelope encryption.
- Keys are loaded into ephemeral worker memory strictly for the duration of a review task.
- Secret rotation is zero-downtime: updating a key in the dashboard immediately switches all ongoing worker threads to the new credential.