Skip to main content
Intervy
← All posts

Bring Your Own AI Key: Privacy & Control in AI Hiring

·Intervy Team·6 min read
Bring Your Own AI Key: Privacy & Control in AI Hiring
On this page

Your security team loves the idea of AI-assisted hiring. They love it right up until someone asks: "So candidate resumes flow through a vendor's AI account, under the vendor's terms, with the vendor's data-retention policy?" Then the project stalls. The capability is fine; the data path is the problem.

This is exactly the gap that "bring your own AI key" closes. Instead of routing AI calls through the platform's provider account, you point Intervy at your own Anthropic or OpenAI account — your key, your terms, your data path.

TL;DR: Bring your own AI key (BYOK) lets your org run Intervy's AI copilot through your own Anthropic or OpenAI account instead of platform credits. You control the data path and your provider's terms, your API key is stored encrypted, and no platform credits are deducted. BYOK is available on Growth and Scale plans.


What "Bring Your Own AI Key" Actually Means

By default, Intervy's AI copilot (Ivy) runs on the platform's own provider account, metered in credits. Bring your own AI key flips that: you supply an API key from your own AI provider, and every AI call your org makes goes through your account instead.

The choice is stored per organization as a provider and a model. Intervy supports three modes:

  • Platform credits — the default. AI runs on Intervy's own account, billed in credits.
  • Your own Anthropic key — Ivy runs on the Claude models you choose.
  • Your own OpenAI key — Ivy runs on the OpenAI model you choose.

Both the provider and the model live in your org settings, so the switch is org-wide and persistent — not something each user has to configure. When a request comes in, Intervy resolves the right provider and builds the AI client from your stored key and model selection.

Worth knowing: Switching providers is an org-management action — it requires organization-management permission, so a random team member can't silently redirect your AI traffic.


Why Bring Your Own AI Key Matters for Hiring Privacy

Hiring data is some of the most sensitive data your company handles — resumes, evaluations, notes about real people. When you bring your own AI key, that data flows through an account you own and govern, under the data-retention and privacy terms you negotiated with your provider.

That's the core privacy win, but it's not the only one:

  • You own the data path. AI calls hit your provider account directly, not a shared platform account. Your provider's enterprise terms, zero-retention agreements, and regional routing apply.
  • Your key is encrypted at rest. Intervy never stores your key in plaintext — it's decrypted only at request time, per call.
  • Provider switches are audited. Every change to your AI provider is logged with the before and after values, so you have a record of who changed what.
  • Settings are org-isolated. Your provider configuration is scoped to your organization — multi-tenant isolation means no cross-org leakage.

For security reviews: BYOK turns "candidate data flows through a vendor's AI account" into "candidate data flows through our AI account, on our terms." That's usually the difference between a stalled procurement and a signed contract.

If reducing risk in your hiring process is a theme for you, it's worth pairing this with the practices in reducing bias in interviews — privacy and fairness are two sides of a defensible AI hiring process.


How Billing Changes When You Bring Your Own AI Key

The most immediate practical effect of bring your own AI key: you stop spending platform credits. When your org runs on your own provider instead of platform credits, the entire credit path is skipped.

That skip is deliberate and total — no credits are charged on the BYOK path. Your credit balance reads zero because credits simply don't apply.

What you give up in credits, you gain in direct billing — you pay your AI provider directly for token usage, at whatever rate your account gets.

Here's the practical comparison:

  • Platform credits (default). Simple, no setup, billed in Intervy credits. Best for getting started or low-volume usage.
  • Bring your own AI key. You pay your provider directly, often at negotiated enterprise rates. Best for high volume, strict data governance, or when you already have provider commitments to spend down.

Usage is still recorded either way — BYOK doesn't make AI usage invisible to your org, it just means the credits column reads zero. You keep visibility without the metering.

Tip: If your team already has an Anthropic or OpenAI enterprise agreement, BYOK lets your AI hiring spend count toward that commitment instead of being a separate line item.


Bring Your Own AI Key Availability: A Growth+ Feature

BYOK is available on Growth and Scale; Free and Starter run on platform credits.

Enforcement happens in two places, which is the right way to gate a feature: it's enforced both when you select a provider and again at request time, so there's no gap between saving a setting and the first AI call that uses it.

There's also a grace window for plan transitions. If your subscription carries a grandfather grant, BYOK keeps working past a downgrade until that window closes. And the fallback is graceful: if the gate lapses, your org doesn't break — it quietly reverts to platform credits instead of failing AI calls.

That combination — feature gate, grace window, soft fallback — means you never hit a hard wall mid-hire. Worst case, you're back on credits, not locked out.

Plan note: BYOK lives on Growth and Scale. If you're evaluating whether to upgrade for it, the deciding factor is usually data governance, not cost — the privacy story is what unblocks security-conscious teams.


Getting Started With Your Own AI Key

If your org is on Growth or Scale, switching is a settings change, not a migration. Decide whether you want to run on Anthropic or OpenAI, generate an API key in that provider's console, and add it under your organization's AI provider settings along with your preferred model.

From that point, Ivy runs on your account. Your resumes and evaluations flow through your provider under your terms. Your platform credits stop draining. And you have an audit record of exactly when the switch happened and who made it.

If you want to see how the AI copilot fits into the broader hiring workflow before you flip the switch, start with the AI copilot feature overview — or read how to prepare for technical interviews with AI to see Ivy in action as a structured interview tool. Either way, bring your own AI key is the option that lets your security team finally say yes.

Related posts