DashCanopy supports Bring Your Own Key (BYOK) workflows. Its server receives the information needed to prepare a provider request and uses your configured key for compatible AI features.
This is the general flow for compatible AI workflows that use a configured OpenAI BYOK key.
You click 'Diagnose Site', 'Find Content Gaps', or any other AI tool in your DashCanopy dashboard.
Our server receives the feature request, reads the encrypted OpenAI key record, decrypts it server-side when needed, and prepares the provider call.
The provider request uses your configured OpenAI key. Provider billing, usage visibility, and data handling are governed by your OpenAI account and its current terms.
The result is returned to the dashboard. DashCanopy may retain feature results and operational records as described in its data-practices materials and settings.
The exact records associated with a workflow depend on the feature you initiate and its settings.
✓ Records used by DashCanopy
✗ Dashboard key protections
Provider key selection
You choose and configure the provider account key used for compatible DashCanopy AI workflows.
Provider-account billing
Provider charges, usage, and account terms are managed through your provider account.
Separate provider account
Your OpenAI account remains separate from your DashCanopy account.
Reviewable configuration
You can review or remove saved BYOK keys from the dashboard settings.
When you save an OpenAI key in Settings → AI Keys, DashCanopy encrypts it with AES-256-CBC and a server-side secret before saving the key record. The stored record contains ciphertext rather than the submitted plaintext value. For a compatible provider request, the service decrypts the value server-side and the dashboard's key-list response remains masked.
Q: Can DashCanopy read my OpenAI key?
A: The service decrypts a saved key server-side when it makes a compatible provider request. Dashboard key listings show a masked value rather than the encrypted stored value.
Q: What happens to my key if I cancel my subscription?
A: Account retention and deletion practices are described in DashCanopy's Privacy Policy. You can remove a saved BYOK key from the dashboard settings.
Q: Does DashCanopy have access to my OpenAI account?
A: DashCanopy uses a saved key only for the provider API requests made by compatible workflows. It does not use your OpenAI web-account login credentials.
Q: What if OpenAI changes their data retention policy?
A: Review OpenAI's current terms and data practices for how it handles requests made with your provider account. DashCanopy cannot set the provider's retention policies.
Configure an OpenAI BYOK key to use compatible AI features, then review the associated settings before starting a workflow.
Questions? Contact support · View changelog