Bring Your Own Key (BYOK)

Configure custom AI provider keys, fallback hierarchies, and private self-hosted inference endpoints.

ScanDrix is model-agnostic. While managed plans include optimized multi-model inference out of the box, teams can supply their own API keys (BYOK) or route inference to private, on-premise models.

Why use BYOK?

  • Direct Provider Billing: Leverage existing enterprise commitments or volume discounts with Anthropic, OpenAI, Google Cloud, or AWS.
  • Data Sovereignty: Ensure all inference requests use your existing zero-data-retention agreements directly with model vendors.
  • Model Choice: Select specialized models per review stage (e.g. fast models for syntax linting, reasoning models for taint analysis).
  • Air-Gapped Privacy: Route requests to local vLLM or Ollama instances inside your private VPC with zero public internet egress.

Supported model providers

Anthropic

Claude 3.5 Sonnet, Claude 3.5 Haiku, Claude 3 Opus via direct API or AWS Bedrock.

OpenAI

GPT-4o, GPT-4o-mini, o1, and o3-mini via OpenAI API or Azure OpenAI Service.

Google Gemini

Gemini 1.5 Pro and Gemini 1.5 Flash via Google AI Studio or Google Cloud Vertex AI.

Self-Hosted / Local

DeepSeek R1, Llama 3.3, and Qwen 2.5 hosted via vLLM, Ollama, or TGI.

Configuring BYOK in the dashboard

1

Navigate to AI Providers

In the ScanDrix dashboard, go to Settings → AI Providers.

2

Add your credentials

Select your target provider (e.g. Anthropic, OpenAI, or Custom OpenAI-Compatible) and paste your API key.

3

Configure model routing

Assign models to specific review pipelines:

  • Taint & Security Analysis: High-reasoning model (e.g. claude-3-5-sonnet-latest or gpt-4o).
  • Fast Linter & Style Rules: Low-latency model (e.g. claude-3-5-haiku-latest or gpt-4o-mini).
4

Test and verify connection

Click Test Connection to send a synthetic health ping and verify quota availability before activating the provider.

Private VPC & local inference (Ollama / vLLM)

For air-gapped environments, ScanDrix supports any OpenAI-compatible HTTP completion endpoint:

yaml
# .scandrix.yaml or dashboard provider config
ai:
  provider: custom_openai
  endpoint: "http://vllm-service.internal.vpc:8000/v1"
  model: "deepseek-ai/DeepSeek-R1-Distill-Qwen-32B"
  api_key: "env:VLLM_INTERNAL_KEY"
  max_tokens: 4096
  temperature: 0.1

Security & key rotation

  • All provider keys are encrypted at rest using AES-256-GCM with tenant-isolated envelope encryption.
  • Keys are loaded into ephemeral worker memory strictly for the duration of a review task.
  • Secret rotation is zero-downtime: updating a key in the dashboard immediately switches all ongoing worker threads to the new credential.