Kcalbin LLC

LLM Broker Exposure Scan

Somebody on your team can point an AI SDK at a cheaper endpoint by changing one line. If that endpoint belongs to a reseller, every prompt, tool call and piece of code in context passes through their infrastructure — and reselling exactly that traffic is a documented business model.

We scan your repositories, environment files and CI configuration and tell you every place your LLM traffic is pointed somewhere that is not your provider.

Why this happens

Not carelessness — economics. The discounts are enormous.

40–93% below list

Founders are openly offered OpenAI and Anthropic usage far below official pricing. Grey-market Claude access has been documented at 70–93% off — in one case about 13 cents of usage per dollar spent.

They keep the keys

The tell is in how it is sold. Rather than handing over provider keys, brokers route your requests through their own endpoint. One broker was reported handling $100,000 of daily spend that way.

Your traffic is the product

A documented secondary revenue stream is logging and reselling user activity — prompts, outputs, tool calls, reasoning traces and code context — as training data. The cheap tokens are paid for twice.

What the scan actually does

A narrow, honest detector. Not a security suite, and we do not pretend otherwise.

Allowlist-first, so it catches endpoints nobody has named yet

A blocklist of known bad domains can never be complete — relay endpoints appear constantly and private relay stations run on throwaway domains. So detection does not depend on one. We check every LLM endpoint against the documented official provider endpoints, and report anything that is not one. Our registry then adds attribution and severity for the hosts we can name.

In testing, a deliberately planted endpoint on a domain absent from the registry was still flagged, because it was not an official provider endpoint. That is the whole design.

Where it looks

What you get back

Pricing

One-time exposure scan

$390 one-time
  • Full scan of your codebase and configuration
  • Written findings report, severity-ranked
  • JSON report for your own tooling
  • Registry as of the scan date, sources cited
Buy a scan — $390

Continuous monitoring

$1,490/year
  • Run the scanner yourself, as often as you like
  • Registry updates as new relay endpoints surface
  • CI-friendly: exits non-zero on findings
  • Re-scan on request
Start monitoring — $1,490/yr

The registry is the part that decays — new endpoints appear constantly — which is why monitoring is the subscription and the scan is not.

What this does not do

Stated plainly, because a detector that overclaims is worse than none.

Delivery and refunds

Digital delivery. There is nothing to ship and no shipping cost.

The one-time scan report is delivered on completion and is final once delivered — the findings cannot be returned once you have seen them.

Annual monitoring carries a full refund within 14 days of the first charge. After that you can cancel at any time; cancellation stops future billing and is not retroactive.

Get started

Buy a scan — $390

Unusually large estimate, or want to talk scope first? Get in touch before buying.