Measuring costs does not require reading conversations.
optidome is built on a simple principle: the financial management of AI is about volumes, costs and licenses, never about what your teams write. That principle is architectural, not contractual.
What optidome sees. What optidome never sees.
| Data | Collected | Why |
|---|---|---|
| Volumes (tokens, credits, seats) and costs | yes | It is the product: measure and price |
| Employee identifier (work email) | yes | Breakdown by team, dormant licenses; can be pseudonymized (HR anonymization) |
| Prompt and answer content | no | Neither stored, nor shown, nor readable by an administrator, including through the gateway |
The Control plan gateway records who, which model, how many tokens, what cost. The text of the exchanges is never written to the database. This behavior is tested automatically at every deployment. The gateway is optional and currently in private beta: optidome works perfectly without it, and you will be able to enable it team by team to enforce your budgets in real time.
The path of your requests, with and without the gateway.
By default, optidome observes your consumption from your vendors' admin APIs, outside the path of your requests. The gateway is an explicit choice, reserved for the Control and Optimize plans, enabled team by team.
The gateway is optional and in private beta. Without it, your requests never pass through optidome. With it, requests transit and only the counters are kept (who, which model, how many tokens, what cost); the text of the exchanges is never written to the database.
Solid line: the path of your AI requests. Dashed: counter collection, read-only, outside that path.
EU-hosted, encrypted, isolated.
- Hosting
- Scaleway (Paris, France). Your data stays in the European Union; daily backups verified with real restores.
- Multi-tenant isolation
- Tenant isolation enforced at the database level (row-level security), not only in the application.
- Secrets
- Your vendor API keys are encrypted at rest (AES-256) and only ever used for reading.
- Authentication
- Enterprise SSO (Entra ID, Google Workspace, OIDC), capped sessions, email verification on first access.
Manage costs without exposing individuals.
One setting replaces identities with stable pseudonyms in every report: totals per team stay accurate, people are no longer exposed. The financial management of AI does not need to know who wrote what.