Why underwriters ask about it
an exposed API key is your AI agent, in an attacker's hands, at your expense.
How to fix it
- Find every API key (they're in the integrations you listed in R6.4) and move them out of email, notes, and shared docs into a password manager.
- Rotate any key that was ever shared loosely, and rotate all keys when someone with access leaves.
- Calendar a twice-yearly rotation.
Evidence to keep
rotation dates noted in the inventory.