Is an AI API Relay Safe? Data Leakage and Model Fakes
AI API relays carry two often-overlooked risks: prompts and responses pass through a third-party server, and models may be swapped for weaker versions.
Two Often-Overlooked Risks of Relays
If you use an AI API relay (forwarding your requests to OpenAI, Claude, Gemini and other original providers), two things are worth understanding first:
1. Data leakage — your prompts and returned content actually enter the relay's own servers first before being forwarded on. What the relay can see, how long it keeps it, and whether it uses it for other purposes depends on the operator, not on you.
2. Model fakes — a relay may publicly claim to offer a certain model, but what it actually calls may be quietly replaced with a cheaper, weaker version that users have difficulty noticing.
These problems are not made up. BazaarLink maintains a public relay testing record page that logs, model by model, the test verdicts for relay endpoints that have accumulated a sufficient sample size (at least 15 tests across more than 5 different dates). These are measurements at specific points in time, not an overall evaluation of any service. A relay's upstream can change at any time, so we recommend reading the methodology and raw data directly rather than looking only at the conclusions.
Solution 1: BYOK, Direct Connection with Your Own Key
BYOK (Bring Your Own Key) lets you use official API keys you obtained yourself from original providers such as OpenAI, Anthropic and Google, calling them through BazaarLink's unified interface. But traffic goes directly to the original provider using your own key, not through a traffic pool that we pay for and resell.
The point is this: BazaarLink is not an intermediary that "pays for you and then resells to you." You pay the original provider's bill, and we provide tools such as a unified interface, key management and budget control. In actual billing, the platform service fee for a successful BYOK direct request is 0. Our own billing logic is written this way too; this is not marketing copy.
To be honest, though: if your own key fails or runs out of quota, the system will by default automatically fall back to BazaarLink's platform pool to keep serving you (only then are those requests billed normally). If you do not want this behavior, you can switch to "strict mode" in the settings. In that case, a BYOK failure returns an error directly and never quietly switches to another channel.
For setup, see the BYOK management page.
Solution 2: Content Filtering, an Extra Layer at the Organization Level
If you run a school or company, personal accounts can turn on protection in the content filtering settings. The organization edition can also be configured centrally under "organization settings" and applied to all members' requests beneath it. There are three selectable actions:
- Block: the entire request is rejected and never sent to the model.
- Redact: matched sensitive content (for example API keys, credit card numbers, national ID numbers) is automatically replaced with
[REDACTED]before being sent. - Flag: the request is sent as usual, but a violation event is recorded for later audit.
This lets administrators block first the kind of leak most likely to cause trouble (for example, someone accidentally pasting the company's internal key into a prompt), without having to watch each member individually.
Migration: Connect With Two Changes
BazaarLink uses the OpenAI-compatible API format common across the industry. If you already connect to OpenRouter or another relay, migration usually requires changing only two things:
- Change the Base URL to
https://bazaarlink.ai/api/v1 - Change the API key to your BazaarLink key (starts with
sk-bl-)
Code and SDK calling methods do not need to change. For BYOK, you additionally attach your own original-provider key in the backend. The two can coexist: general models go through the platform pool, and specific models use your own key.
Frequently Asked Questions
TWD billing · Taiwan invoices · leading AI models · OpenAI-compatible API