CHAPTER 11 · Security, Auth, and Multi-Tenancy · 7 / 9
Secrets and keys
User and system credentials (model-provider keys, integration tokens) must be encrypted at rest and never exposed to clients. This is important enough to get its own chapter (Chapter 12).