Where your API key lives

Last updated 20 September 2026

ansvery runs on your own OpenAI or Gemini API key. That is a real thing to hand over, so this page says plainly what happens to it, what we store, what we do not, and how you take it back.

The short version

What we store, and what we do not

The split matters more than any promise, because a database dump is only as dangerous as what is in it.

Stored

Not stored in the application database

A mask is not a secret. If the application database leaked tomorrow, it would not contain a usable key — which is the entire reason the key is kept somewhere else.

Rotating or removing your key

Because there is no read-back path, rotation works the way it should: you issue a new key at OpenAI or Google, paste it into ansvery, and delete the old one at your provider. Nothing has to be recovered from us.

If you want ansvery to stop making calls immediately and do not want to wait for anything on our side, revoke the key in your OpenAI or Google console. That takes effect at the provider, not at us, which is the point of bring-your-own-key.

What the AI provider receives

When an AI agent answers a ticket, the content of that conversation and the relevant knowledge-base context are sent to the provider your key belongs to — OpenAI or Google — under your own account and their terms. ansvery does not route your traffic through a shared or resold model account.

This means your provider's data-handling terms apply directly to you, and any enterprise agreement, region setting or data-retention option you have with them applies to your ansvery usage too.

Transport and access

Compliance, honestly stated

We are not going to claim certifications we do not hold. ansvery does not currently advertise SOC 2 or ISO 27001. What we can do is answer specific questions in writing before you commit a key — including a data processing agreement, subprocessor list, retention periods and deletion timelines for your account.

If your security review needs those documents, ask during onboarding and we will send them rather than pointing you at a badge.

Reporting a vulnerability

If you find a security issue, email info@ansvery.com with enough detail to reproduce it. We would much rather hear from you than from someone else.

Related

See the privacy policy for how personal data is handled, and the FAQ for how the free bring-your-own-key model works.