Skip to main content
AI PublishMulti-Site AI Article Publishing Platform

Feature / BYOK & Security

Your keys, our protection

Adopting an AI writing platform always comes down to two authorizations: your AI provider API key, and publish access to your sites. AI Publish answers both with BYOK plus a complete key-protection and permission-boundary model.

Why bring your own key

  • Transparent cost: model fees are charged directly by your AI provider with no platform markup — the provider bill is the real cost.
  • Model freedom: different tasks can bind different providers and models, avoiding lock-in to a single model.
  • Swap anytime: adding, rotating and deleting keys is fully in your hands — no support ticket required.

How keys are protected

  • Encrypted at rest: API keys are stored encrypted and never echoed in full anywhere in the interface.
  • Rotatable and revocable: rotating a key never disturbs the configuration snapshots of past tasks; deleting a key immediately stops all calls that used it.
  • Audited: every key configuration and change lands in the audit log.

Full encryption, request-signing and incident-response details are in the Security Center.

Connector permission boundaries

The connector you upload to the site root does exactly one thing: relay publish requests between the platform and your CMS under strict controls.

  • Signed, timestamped requests: the connector verifies signatures and timestamps, rejecting replayed or forged requests.
  • Limited operation scope: connectors only perform article-related publish actions, never touching other site data.
  • Removable at any time: deleting the site or removing the connector cuts off all access — no usable publish channel remains on the platform side.

Data retention and deletion

  • Clear data flows: article content is generated by the model you configure, scheduled by the platform and published to your site. See the data processing notice.
  • Deletion on demand: keys, site connections and historical tasks can all be deleted, after which a cleanup process takes over.
  • Plan expiry: post-expiry retention periods and backup cleanup rules are documented item by item in the privacy policy.

FAQ

  • Can administrators see my key? No — keys are encrypted and never echoed, including in the admin console.
  • Does rotating a key affect running tasks? No. Running tasks use the snapshot captured at submission; new tasks pick up the new key afterward.
  • What about provider data policies? Your key interacts with the model provider directly, so the provider's data terms govern that relationship; the platform-side data scope is documented in the privacy policy.

Your keys, our protection

Adopting an AI writing platform always comes down to two authorizations: your AI provider API key, and publish access to your sites. AI Publish answers both with BYOK plus a complete key-protection and permission-boundary model.