Bring your own subscriptions

Your credentials never leave your machine.

Your team already pays for Claude, ChatGPT, and OpenAI. When an agent fleet runs hard enough, a single plan stalls — and the work stops mid-flight. Penstock keeps those subscriptions in a vault you hold, and routes across them from one endpoint.

That claim above is the Private Vault grade — credentials on hardware you control. It is the strongest rung of a three-rung custody ladder, and it is the only rung where "never left my machine" is literally true. The other two say so plainly.

Private, invite-gated beta.

The custody line Three zones. Your machine holds the credentials and is separated by the custody line from the Penstock plane, which routes requests out to the providers. Credentials terminate inside your machine and never cross the line; only request metadata crosses. YOUR MACHINE macbook-pro.local VAULT vault:macbook-pro-ora ▓▓▓▓▓▓▓▓▓▓▓▓ Claude subscription ▓▓▓▓▓▓▓▓▓▓▓▓ ChatGPT subscription node-signed · Penstock cannot read this CUSTODY LINE — CREDENTIALS DO NOT CROSS PENSTOCK PLANE One endpoint api.penstock.run Selects a subscription, shapes and retries the request, records a trace. What crosses the line Request metadata, routing state, and traces — no credential material. PROVIDERS Anthropic OpenAI Your accounts, your entitlements. Penstock does not operate them.
The custody line is a permanent part of this product's design, not a promise in a paragraph. Every Penstock surface knows which side of it you are looking at.

SUBSCRIPTION STATES

  • Flowing
  • Refresh due
  • Action needed
  • Tripped

Every state names its remedy inline. A state with no next action is a bug.

How it works

Connect the subscriptions you own. Point your agents at one URL.

Penstock does not sell tokens and does not run provider accounts on your behalf. The capacity is yours; the control plane is what you are buying.

  1. 01

    Commission your vault

    Install the local helper and pair it. Penstock walks a Commissioning Record — helper installed, lamp test, node paired, custody line verified, subscription connected, provider loop closed, tool loop closed — and each line stamps as it completes. Grades that use a home device add an egress linked stamp after custody verification. You confirm the redaction bars in the console match your own machine's output, so the custody claim is something you check rather than something we assert.

  2. 02

    Connect a subscription

    Sign in to Claude, ChatGPT, or an OpenAI API key through the helper, on your side of the line. The credential is written into your vault. Penstock receives the fact that a subscription exists and is usable — never the credential itself.

  3. 03

    Point your agents at one endpoint

    Set base_url to api.penstock.run. Your existing OpenAI and Anthropic SDKs work unchanged. Penstock picks a subscription with headroom, shapes and retries the request, fails over to a sibling subscription when one is rate limited, and writes a trace you can read.

Custody

Three rungs. Each one tells you the truth about itself.

Where your credential is allowed to live is a real trade-off, so Penstock detects what your hardware can do, defaults you to the strongest rung it supports, and states the trade-off plainly. It is not a topology quiz, and the honest answer is never buried.

  • Private Vault

    Credential lives on hardware you control

    ▓▓▓▓▓▓▓ on your hardware

    Credential never leaves macbook-pro.local. Penstock cannot read or refresh it remotely.

    The only rung where "it never left my machine" is literally true.

  • Verified Cloud Vault

    Credential lives in a Penstock-operated cloud vault

    Default when your hardware has no secure element

    ▓▓▓▓▓▓▓ penstock cloud vault

    Credential is held in Penstock-operated cloud vault vault-sfo12-b, not on hardware you control.

    No custody proof is claimed for this rung, because there is none to show.

  • Cloud Vault

    Credential lives in a cloud vault process

    Explicit downgrade — gives up residential egress

    ▓▓▓▓▓▓▓ cloud vault process

    Convenience mode — gives up residential egress. Credential is isolated in a cloud vault process, not on hardware you control.

    Offered because it is sometimes the right call. It is the one rung that trades something away, so the console carries that trade-off as a standing marker for as long as this grade is in effect.

Penstock's own console draws the same three variants for your own vaults. If a claim on this page and a claim in the product ever disagree, the product is the one telling the truth.

Platform

What the control plane does with capacity it does not own.

One endpoint, unchanged SDKs

Claude and OpenAI behind a single base URL. Your existing clients work as they are — switch which subscription serves a request without switching libraries.

Routing across your own subscriptions

Penstock tracks headroom per subscription and picks one that can serve. When a provider rate-limits, it fails over to a sibling subscription you connected — and demotes the limited one rather than dropping it.

Metering on both ends

Rolling 5-hour and weekly window meters per subscription, with reset countdowns, so an exhausted plan reads as capacity rather than as an error. Idle reads as zeroed meters — itself a signal.

Traces you can actually follow

Per-request traces with model, duration, outcome, and the subscription that served it. Drill into a live session to see its entries, the tools it invoked, and the context it matched.

Custody kept out of Penstock's reach

Credentials and provider sessions stay behind your custody line. Penstock's control plane receives routing state and traces, never credential material — and its own surfaces show you where its visibility stops.

Penstock Context Private beta

An opt-in memory layer that enriches a request with your team's own knowledge, so you can write shorter prompts and get project-aware answers. Off unless you turn it on, per org.

Zero data retention on the proxy path: your prompts are not used to train models and are not shared between customers.

Pricing

You pay Penstock for the control plane. The capacity stays yours.

Penstock is not a token reseller — there is no Penstock inventory to buy. You keep paying your providers directly for the subscriptions you already have, and you pay Penstock to route, meter, trace, and govern across them. Tiers below describe structure; we set real numbers with you during beta.

Starter

For a small team pointing its first agents at a shared endpoint.

  • One endpoint for Claude & OpenAI
  • Connect your own subscriptions
  • Routing, retries & failover across them
  • Window meters & request traces
  • Community support
Request access

Enterprise

For organizations that have to answer for where credentials live.

  • Everything in Pro, plus:
  • SSO & org/role controls
  • Per-org isolation & audit trails
  • Data-handling review
  • Custom commercial terms
  • Dedicated support
Contact us

Reliability target: 99.5% uptime on the control plane, designed to fail over across your connected subscriptions. Tier capabilities describe structure; final pricing is set with you during beta.

Ready to put your own subscriptions behind one endpoint?

Penstock is in private, invite-gated beta. Tell us what you're running and we'll get you an endpoint, a key, and a vault to commission.