What Is a BYO Key AI Portal, and Why Do IT and Security Buyers in Financial Services Want One?
Salesforce AI

What Is a BYO Key AI Portal, and Why Do IT and Security Buyers in Financial Services Want One?

By Troy Amyett•October 9, 2026•12 min read
Book Intro Call
Back to Insights

A BYO Key AI portal is a customer or partner portal whose AI assistant runs on your own LLM provider account. You supply the API key for OpenAI, Anthropic, Google, or xAI, so your company is billed for inference directly, your own contract with that provider governs what happens to prompts and responses, and you can change providers without rebuilding the portal. For IT and security leaders at lenders, insurers, and other regulated financial firms, that is the difference between AI they can sign off on and AI they have to take on trust.

One clarification first, because the acronym causes real confusion. BYO Key in this post is not to be confused with Salesforce Shield Platform Encryption BYOK. The two share an acronym and are unrelated. This post is only about the key that decides which AI model answers your customers, and who pays for it.

Who is asking for this, and what they are stuck on

The person who asks for a BYO Key AI portal is usually the head of IT or information security at a mid-market financial services company that runs on Salesforce. The business side wants AI in the customer or partner portal: answer “where is my application?” questions, explain a document, route a request to the right team. The security side has to approve it, and the questions they ask are always the same:

  • Which model will read our customers’ questions?
  • Where do the prompts and responses go, and can the provider train on them?
  • Whose contract covers that data: ours, or a software vendor’s?
  • If the provider changes its terms or its model, can we move?
  • Who sees the AI bill, and can we tie it to the portal that created it?

Most portal AI is bundled. The platform vendor picks the model, signs the provider contract, and meters usage on its own terms. That can be perfectly fine for an internal pilot. For a security reviewer at a regulated lender, it means approving a chain of subprocessors they did not choose and cannot easily exit.

The pressure to answer these questions is rising, not falling. Salesforce and Anthropic announced Claudeforce on August 26, 2026, and at Dreamforce in September Salesforce unveiled AIforce, an interface layer meant to bring Salesforce data, permissions, and governance into outside AI tools. Outside models are now a normal part of Salesforce architecture. The open question for a security team is no longer whether customer data will meet an LLM. It is under whose key, and whose contract.

There is a second, quieter problem: the portal itself. Experience Cloud external users are licensed per member or per login, so the portal’s cost grows with every customer or partner you invite, before any AI is added.

What a BYO Key AI portal actually controls

The key is a small thing that settles several big questions at once.

Which provider and model run. Your team chooses the provider your security group has already reviewed. If you approved Anthropic last year, the portal uses Anthropic. Nobody slips a different model in behind a product update.

Who is billed. Inference charges land on your provider invoice, not inside a platform fee. Finance can see exactly what the portal’s assistant costs, and you can set spend limits with the provider directly.

Whose contract governs the data. You are reading the provider’s business terms yourself, not a reseller’s summary of them. For example, OpenAI states that API inputs and outputs are not used to train its models by default, and Anthropic states that it does not train on commercial customers’ API content by default. With BYO Key, those terms apply to your account because it is your account.

Whether you can leave. Because the key is a setting rather than a dependency baked into the code, switching providers is a configuration change. That is the practical meaning of vendor-neutral AI: the portal’s capability is defined separately from the model that runs it.

What it does not change. Salesforce still decides what each person can see. Sharing rules, profiles, and field-level security apply to the assistant exactly as they apply to the portal pages. A well-built assistant retrieves only records the signed-in member could already open, and grounds its answers in that data instead of guessing.

That last point is why we describe data sovereignty in plain terms. It does not mean cryptography. It means you own the code, you own the Salesforce org the data lives in, and you own the AI key. Your key, your contract, no model lock-in.

How Funnelists approaches it as your AI advisor

We treat the AI decisions as the main event and the portal as the way to deliver them. Before anything is configured, we work through the questions your security team will ask anyway:

  • Which provider is already approved, or closest to approval, under your vendor review process?
  • Which objects and documents may the assistant read, and which are off limits?
  • What must it never answer, and when must it hand off to a person or open a case?
  • Who owns the key, who rotates it, and who watches the spend?
  • How will you review answers after launch, and who decides when to change models?

Then we put those decisions into a working portal. The SF Custom Portal Template includes an AI assistant built on BYO Key: connect a supported LLM provider and it answers from your own knowledge, documents, and Salesforce records. If you would rather run Salesforce’s own agent, the same portal can switch to Agentforce, a path we cover in adding Agentforce to a custom portal without Experience Cloud. The portal runs inside your org, and you can invite members without a per-login Experience Cloud license, which removes the portal cost problem described above.

For most clients the portal is the first project, not the last. Once the provider, the guardrails, and the review routine are in place for one portal, the same decisions carry over to the next AI use case, whether that is a service agent, an internal assistant, or connecting Claude or OpenAI to Salesforce under governed access.

The honest limitations

BYO Key moves responsibility to you, and that is worth saying out loud.

  • You own the provider relationship. Key rotation, spend monitoring, rate limits, and provider outages are your team’s job, with our help, rather than a platform vendor’s.
  • Models change. Providers update and retire models on their own schedule. You need a simple routine to re-check answers when that happens.
  • It is not a compliance certificate. BYO Key makes the data path explainable. Your compliance team still has to review the provider’s terms against your own obligations.
  • Salesforce has its own option. If all of your AI lives inside Agentforce and Prompt Builder, Salesforce’s AI Models feature already lets you bring your own model from OpenAI, Azure OpenAI, Google Vertex AI, or Amazon Bedrock using your own credentials. In that case a separate portal-level key may be unnecessary, and we will tell you so.

Does BYO Key alone protect financial services data?

No. BYO Key decides which provider and which account handle your prompts. It does not decide how long that provider keeps them. Retention and training terms come from your contract with the provider, so the key is only as protective as the terms behind it.

Standard API terms can keep prompts and responses for a period, typically for abuse monitoring. As of October 9, 2026, OpenAI’s documentation says abuse monitoring logs, which may include prompts and responses, are retained for up to 30 days by default, and Google Cloud says it may log prompts for up to 90 days when its classifiers flag suspicious activity. Not training on your data is a different promise from not keeping it.

The major providers do offer stronger terms for eligible customers, usually by approval rather than by default:

For a lender, insurer, or wealth firm, the practical rule is simple. Before customer data reaches the assistant, confirm that your provider account has ZDR or equivalent retention terms in writing, check which models and features those terms actually cover, and have your compliance team sign off against your own obligations. Without that, keep sensitive fields out of prompts. As your AI advisor, Funnelists reviews the provider terms, the models you plan to use, and the data the portal will send with your team before go-live.

Decision framework: bundled AI or BYO Key?

Use these criteria to place yourself honestly.

A BYO Key AI portal is the better fit when:

  • Your security team already has an approved contract with a specific LLM provider.
  • You need to explain to examiners, your internal risk team, or your board exactly where customer prompts go and who processes them.
  • You want inference costs on your own invoice so they can be tied to the portal.
  • You expect to change providers as models improve, and do not want a rebuild each time.
  • The portal serves many external customers or partners, so per-login licensing is already a budget conversation.

Bundled platform AI is the better fit when:

  • AI use is light, internal, and low-risk, such as summarizing records for employees.
  • You are standardized on Agentforce and comfortable with Salesforce-managed models.
  • Nobody on your team can own a provider account, its keys, and its spend.

If you land in between, that is exactly the conversation we have on a free 30-minute intro call. Bring the provider your security team prefers and a rough list of the data your portal would touch, and we will tell you which way we would go and why.

FAQ

What is a BYO Key AI portal?

It is a customer or partner portal whose AI assistant uses your own LLM provider API key, such as an OpenAI or Anthropic key. Your company chooses the model, is billed directly by the provider, and works under its own contract with that provider.

Is BYO Key the same as Salesforce Shield BYOK?

No. They share an acronym but are unrelated. Shield BYOK concerns Salesforce encryption keys. BYO Key for an AI portal concerns which LLM provider runs the assistant and who pays for and governs that usage.

Who pays for the AI usage in a BYO Key portal?

You do, directly. Inference charges appear on your own provider account, which makes the cost visible and easy to attribute to the portal.

Why shouldn’t my AI portal be locked to one LLM provider?

Models, terms, and quality change quickly. If the provider is a setting rather than part of the code, you can move when your security review, your budget, or answer quality says you should, without rebuilding the portal.

How do I keep AI data sovereignty on Salesforce customer data?

Own the three things that matter: the code, the Salesforce org the data lives in, and the AI key. Then make sure the assistant respects your existing sharing rules and field-level security, so it can only read what each user is already allowed to see.

Does a BYO Key assistant bypass Salesforce permissions?

It should not, and a well-built one does not. The assistant retrieves data as the signed-in member, so Salesforce sharing rules and field-level security still decide what it can read.

Do financial services firms need a zero data retention agreement for BYO Key?

Often, yes, and your compliance team should decide. BYO Key controls which provider and account are used, but the provider’s contract controls retention. Standard API terms can keep prompts for abuse monitoring, so regulated firms should confirm Zero Data Retention or equivalent terms with OpenAI, Anthropic, Azure OpenAI, or Google before customer data flows through the portal.

The takeaway

For an IT or security buyer in financial services, the AI question that matters is not which model is smartest this quarter. It is who controls the model, the contract, and the bill. A BYO Key AI portal answers all three with “you do,” while Salesforce keeps deciding who sees what. Settle those decisions first, and the portal becomes a safe place to start putting AI in front of customers.

Troy Amyett

Troy Amyett

Founder & Chief Solutions Architect

9x Salesforce certified. Agentforce Specialist and Agentblazer Legend, 2025–2026. Anthropic-certified in Claude Code and MCP.

Get Insights in your inbox

AI-powered perspectives on Salesforce and Agentforce, delivered weekly.

No spam. Unsubscribe anytime.

Ready to Put AI to Work?

Let's talk about what AI agents could do for your business. 30 minutes. No pitch deck. Just answers.

Book Intro Call