All articles

Product

BYOK LLM Routing for Security Reviews

Bringing your own model key is a privacy decision with real architectural consequences. What changes in the review pipeline, and what does not.

ScanDrix EngineeringPlatformFebruary 3, 20268 min

Bring-your-own-key is usually sold as a line item. It is closer to an architectural commitment: once a customer can supply their own inference endpoint, the review pipeline can no longer assume it controls the model boundary.

The model is a swappable dependency

The deterministic half of a ScanDrix review is model-independent. Tree-sitter parsing, taint propagation, rule evaluation, and severity assignment all happen before any model is called. The model is used for intent classification and patch drafting.

That split is what makes BYOK tractable. Swapping providers changes the second half only, and the first half — the part that produces most findings — is unaffected.

  • Deterministic pass: parse, propagate taint, evaluate Drixy rules, assign severity.
  • Model pass: classify intent, explain the finding, draft the patch.
  • Provider abstraction: Anthropic, OpenAI, Gemini, or a self-hosted vLLM / Ollama endpoint.

Self-hosted endpoints change the deployment story

Pointing at an internal vLLM endpoint is the configuration most often paired with a VPC deployment, and it is the one that requires the most care. The internal endpoint is frequently air-gapped, which means the review pipeline needs a complete local path — no fallback to a hosted provider.

A silent fallback to a public API is the failure mode to avoid at all costs, because it would move code outside the network boundary the customer paid to build. Fail loudly instead: if the configured endpoint is unreachable, fail the review and report it.

SCANDRIX_LLM_PROVIDER=custom
SCANDRIX_LLM_BASE_URL=http://llm.internal.vpc:8000/v1
SCANDRIX_LLM_MODEL=scandrix-review-14b
SCANDRIX_LLM_ALLOW_PUBLIC_FALLBACK=false

What BYOK does not change

Your code still transits our ephemeral analysis tier, and we still process diffs server-side to parse them. BYOK governs where model inference happens, not where parsing happens. For customers whose threat model forbids both, the answer is a self-hosted deployment, where the entire stack — API, queue, AST workers, and model — runs inside their own network.

If you are evaluating this for a compliance requirement, the question to ask is whether you need model locality or full-stack locality. They are different products, and only one of them is a VPC deployment.