Appearance
AI Provider Security & Credential Protection
OrviQ ensures that customer-supplied AI credentials and data boundaries are safeguarded across all AI operations.
Credential Protection Principles
- Security Vault Encryption: Customer Bring-Your-Own-API keys are encrypted using the platform security vault before being written to the database.
- Zero Plaintext Exposure: Secret API keys are never returned in client API responses or displayed in user interfaces after entry.
- Granular Provider Scoping: AI credentials are strictly scoped to the configuring tenant.
- Telemetry & Provenance: AI requests are logged with task family, provider, model name, token usage, and latency metadata for governance tracking without logging sensitive message payloads.