Skip to content
SealMetrics
Product

Seal AI vs Bring-Your-Own-Key: When to Use Each

5 min readBy Rafa Jiménez

Seal AI is the default because privacy should not depend on a checkbox. But you can bring your own OpenAI, Anthropic, Gemini or DeepSeek key if you need a specific model — you just take on the terms, the cost and the transfer analysis that come with it.

Key Takeaways

  • Seal AI is the default: no key, no AI vendor account, EU-only inference, zero retention, no training, covered by your plan quota.
  • Bring-your-own-key buys model choice. In exchange, your prompts run under your provider's terms and jurisdiction, and the usage is not metered by us.
  • A US-parent provider means CLOUD Act exposure even with an EU region — with your own key, that assessment becomes yours to run and document.
  • It is a setting, not a migration. Switch either way at any time; the assistant behaves the same, only the model and the terms change.

Most products that offer both a managed AI and a bring-your-own-key option quietly push you towards whichever one is cheaper for them. This post does the opposite: here is what each option genuinely costs you, so you can pick once and stop thinking about it.

Seal AI: the default, and why it is the default

Seal AI is the private AI layer inside SealMetrics. It powers the natural-language assistant and the automated insights, and there is nothing to configure — no API key, no AI vendor account, no onboarding step where you paste a secret into a settings page. The platform holds the key; you never see it.

What that gets you, specifically:

  • Inference in Paris, France only, on Scaleway's Generative APIs. Scaleway is a French company in the Iliad group with no US ownership, and states explicitly that its AI services are not subject to extraterritorial laws such as the American CLOUD Act.
  • Zero data retention by default and no training on your data. The documented exception is narrow: on a severe service error, the failing request may be kept for up to two weeks for root-cause analysis.
  • No international transfer at all, so GDPR Chapter V — Article 44 onward — is not triggered. No Standard Contractual Clauses, no Transfer Impact Assessment, no reliance on the EU-US Data Privacy Framework.
  • Only token counters persist. Organisation, model, input and output token counts, for quota and billing. Prompt and response content is never persisted by the metering layer.
  • Covered by your plan. Usage draws on your organisation's token quota, with non-expiring token packs available if you need more headroom.

There is one more property worth naming, because it is upstream of everything above. SealMetrics is consentless analytics: it never collects IP addresses, cookies, fingerprints or visitor identifiers at all. There is no personal identifier in the dataset to send to a model in the first place. The prompt is born clean.

Bring-your-own-key: what you gain, what you take on

You can connect your own OpenAI, Anthropic, Gemini or DeepSeek key instead. The assistant works the same way — same questions, same tool inventory, same interface — but the inference goes to your provider on your account.

What you gain is real: model choice. If your team has standardised on a particular model, if you have already negotiated pricing with a provider, or if internal policy requires AI spend to run through your own contracts, this is the option that fits.

What you take on is also real:

  • The data-transfer analysis. Your prompts go to that provider under that provider's terms, including its jurisdiction. If the provider has a US parent, an EU region gives you residency but not sovereignty — CLOUD Act exposure follows the corporate parent, not the datacenter. Documenting that position becomes your job, not ours.
  • The cost. You are billed directly by the provider. Bring-your-own-key usage is not metered by SealMetrics, which means no quota ceiling from us and no visibility from us either.
  • The key management. Rotation, scope, revocation, and knowing who in your organisation can see it.
  • The provider's retention and training defaults. These vary considerably. Worth reading closely before connecting: DeepSeek's official API, for example, states in its privacy policy that it stores personal data in the People's Republic of China and uses data to train and improve its models, with an opt-out exercised by email. Italy's data protection authority imposed an urgent processing block on it in January 2025. The open weights are a separate matter — it is the official API that carries these terms.

None of that makes bring-your-own-key a bad option. It makes it an option with homework.

Side by side

AspectSeal AI (default)Bring-your-own-key
SetupNone — no API key, no AI vendor accountYou create and manage a provider key
Model choiceThe model we ship and test (gpt-oss-120b)Yours — OpenAI, Anthropic, Gemini or DeepSeek
Where inference runsParis, France only. No US parentWherever your provider processes it
Retention & trainingZero retention by default, no training on your dataWhatever your provider's terms say
Who you payNobody extra — covered by your plan quotaYour provider, directly, at their prices
MeteringToken counters per organisation, for quota onlyNot metered by SealMetrics
Transfer analysisNot triggered — no international transferYours to run and document

How to choose in one minute

Choose Seal AI if you want the assistant to work the moment you open it; if you operate in the EU and would rather not run a transfer assessment for an analytics feature; if you have no strong opinion about which model answers your questions; if you want AI usage to sit inside your existing plan rather than a separate vendor bill; or if you simply do not want another API key in your organisation.

Choose bring-your-own-key if you need a specific model for a specific reason; if your organisation already has a provider contract that AI spend must flow through; if an internal policy requires inference on your own account; or if you want to evaluate a model against your own data before standardising on it.

If neither list is decisive, the answer is Seal AI. The default exists so that the privacy-preserving path is the one you get without doing anything — a guarantee that depends on a customer finding the right setting is not much of a guarantee.

You are not locked into either

This is a setting, not an architecture decision you live with forever. Start on Seal AI, connect your own key later if a requirement appears, disconnect it and fall back to the default if it does not work out. The assistant, the 63-tool inventory and the way you phrase questions do not change — only the model behind them and the terms it runs under.

The full processing detail, subprocessor listing and compliance position are documented in the Seal AI architecture and privacy documentation. For the jurisdiction question behind the bring-your-own-key trade-off, see Residency Is Not Sovereignty.

Related reading