BYOAIK (Bring Your Own AI Key) is a directory of AI tools that run on your own API key.

SurfSense

Open-source, privacy-focused NotebookLM / Perplexity / Glean alternative that connects any LLM to your docs and external sources.

Website Source code

Category:
Research Tools
Maintenance:
Actively developed (last commit yesterday)
Pricing:
Open Source
Open source:
Yes (Apache-2.0)
Self-hostable:
Yes
Local-first:
Yes
Platforms:
Web, Self-hosted, Docker
AI providers (bring your own key):
OpenAI, Anthropic, Google Gemini, Groq, DeepSeek, Ollama, Custom / OpenAI-compatible
API key storage:
User controls deployment
Key risk level:
LOW
Trust score:
83/100

SurfSense is a self-hostable, open-source research and knowledge assistant positioned as a private alternative to NotebookLM, Perplexity, and Glean. It connects your own LLM to internal documents and external sources (search engines like Tavily/LinkUp/SearxNG, plus Slack, Notion, Linear, Jira, Confluence, GitHub, YouTube, Google Drive and more) and answers with cited hybrid (semantic + full-text) search, generating reports, podcasts, and chats over your knowledge base. It is BYOK by design: the dashboard lets users create custom LLM configurations by entering their own API credentials, selecting models, and defining custom API base URLs, with all calls routed through LiteLLM for 100+ providers. A CUSTOM/custom_provider option supports any OpenAI-compatible endpoint, and it can run fully local with no OpenAI key via Ollama or vLLM. It is deployed via Docker/Docker Compose or manual installation on your own infrastructure. Verified via GitHub API (15,033 stars, Apache-2.0, not archived, pushed 2026-06-20, v0.0.29) and corroborated by README, the official site, and codebase analysis of the LLM config/API-key management system.

Why this trust score (83/100)

Trust measures how the tool treats your API key and how much of that has been verified. It contains no popularity signal.

  • Key Safety 21/25: The key lives in a deployment you run yourself.
  • Request Routing 17/20: Requests go straight from you to the AI provider.
  • Transparency 20/20: Source is public under Apache-2.0, so anyone can check how the key is handled.
  • Privacy 14/15: Local-first: it works without sending your data anywhere. Can be self-hosted, so the data path stays inside infrastructure you control.
  • Maintenance 10/10: Actively developed: commits within the last three months.
  • Verification Confidence 1/10: Compiled from public documentation by an AI-assisted pass, not independently confirmed.

What was checked

Verification tier RESEARCH_ASSISTED, derived from the evidence below and not set by hand.

  • [REPORTED · RESEARCH] This listing was compiled by an AI-assisted research pass over the tool's public website, README and documentation. No person independently confirmed it.
  • [STRONG · SOURCE_SCAN] Supports a local model backend, so it can run with no cloud provider key at all. source
  • [CONFIRMED · SOURCE_SCAN] Most recent commit 2026-08-07, about 0 month(s) ago. source

How your API key is handled

You self-host the app, so your API key lives in your own deployment. Requests are sent directly to the AI provider. Because it can be self-hosted, your key never has to touch a third-party backend.

Setup

Deploy it (Docker/compose), add your provider API key in the admin or environment config, then select models.