Glossary

BYOC (Bring Your Own Cloud)

BYOC (Bring Your Own Cloud) is a model where a customer connects their existing cloud provider account instead of migrating to a vendor's own infrastructure or a reseller's account. The account, contract, and billing relationship stay with the customer and the provider throughout; the vendor manages resources inside it rather than owning them.

BYOC describes who legally owns the cloud account a piece of infrastructure runs in, not who operates it day to day. In a BYOC arrangement, an organization keeps its own account with a cloud provider — Amazon Web Services, Google Cloud, Hetzner, or any other — along with the contract and invoice that comes with it. A separate vendor, such as a management platform, monitoring tool, or managed-service provider, is given scoped access to operate inside that account: provisioning resources, applying configuration, or collecting telemetry. Nothing about the underlying compute, storage, or networking moves. The term originated in managed-database and SaaS contexts, where 'bring your own cloud' distinguishes a deployment that runs inside the customer's account from one hosted entirely on the vendor's own infrastructure.

The alternative is a fully managed or reseller model, where the vendor holds its own account with the underlying provider and either resells capacity to customers or migrates their workloads onto infrastructure it owns outright. That model can simplify billing — one vendor, one invoice — but it also means the customer's infrastructure exists inside someone else's account. Switching vendors, negotiating provider pricing directly, or proving to an auditor exactly which entity holds the underlying contract all become harder. BYOC keeps that boundary intact: the customer can revoke the vendor's access at the provider level at any time, and the underlying account, its billing history, and its compliance posture never change hands.

In practice, BYOC access is granted through API credentials or a role the vendor is given inside the customer's account, scoped to what it actually needs and revocable independently of the vendor relationship itself. The trade-off is operational: the customer, not the vendor, remains the contracting party with each cloud provider, so multiple providers mean multiple contracts and invoices unless something above the account layer consolidates them. Vendors that support BYOC typically also support the opposite model — provisioning and billing capacity under their own account on the customer's behalf — so an organization can mix both depending on which resources it wants to keep under direct provider contract and which it is comfortable delegating entirely.

Why BYOC matters

Lock-in is the central risk BYOC addresses. When infrastructure sits inside a vendor's own account, leaving that vendor means migrating workloads — a project measured in weeks or months, not a support ticket. BYOC makes an exit a permission change: revoke the vendor's credentials and the infrastructure is exactly where it was, under the same contract. That matters most where the underlying account, not just the data, has compliance weight — regulated industries where a specific legal entity must remain the data controller's direct contracting party with the infrastructure provider, or public-sector procurement rules that require the buying organization to hold its own cloud contract rather than a subcontracted one. It also preserves whatever volume pricing or enterprise agreement the organization already negotiated directly with its cloud provider.

How Sencai handles BYOC

Sencai supports BYOC as one of two coexisting models in the same organization. Connect an existing account and nothing moves: credentials are encrypted at rest, you can revoke access at the provider any time, and the moment the account is connected Sencai inventories what's already running — instances, networks, storage, DNS — across every connected provider, with resource-by-resource opt-in to active management. The account, contract, and invoice stay with your provider throughout. If you'd rather not hold a direct provider contract, Sencai can provision and bill capacity under its own account instead — one invoice, provider cost plus a 2% margin shown separately on the statement — and you can mix both models as needs change.

See how inventory and provisioning works →