Can we bring our own model keys or private endpoints?
Yes. Each deployment has an explicit provider allow-list, and a private inference gateway keeps model traffic inside your network. Your own provider account is not a subprocessor.
Model providers are enabled per deployment through an explicit allow-list: your cloud's model service, a provider account you hold, a gateway you operate, or a proxy such as LiteLLM in front of several. A VPC deployment can reach models over a private endpoint so inference traffic never crosses the public internet.
When you supply the provider account, that provider is your vendor, not a Context subprocessor, and its retention terms are the ones you signed. The Inference page describes private endpoints and dedicated capacity.
Written for deployment engineers, it and security. Last reviewed 2026-09-15.
Related questions
Still need an answer?
Tell us what you were looking for and we reply within one business day.
Contact the team →Running a security review?
Documents, controls, and the request form live in the Trust Center.
Open the Trust Center →