# Bring your own key

In the local app, Pi will read your own provider credential from its credential store on the machine. The local app will need no muniment cloud key and send no provider credential to the paid console. In the paid console, the console owner will store provider keys once for every paid route to use. No user machine will hold a company key.

These features will be available at launch. muniment is [not generally available](/docs/). The rest of this guide describes the paid console.

## Set the credential

The console owner will set provider keys in the [Models area of the paid console](/docs/#paid-console).

## How the provider vault holds it

The paid console’s [provider vault will encrypt each provider key](/security/#security-keys-title) at rest and keep it off user machines.

Each [tenant will have its own subdomain](/security/#security-architecture-title). The paid console will keep each tenant’s provider keys, records, and policy separate. The [provider vault runbook](/docs/connections/provider-vault/) covers deployment-key operations.

## Audit records

The [audit records guide explains which actions create records](/docs/audit-records/).
