R6.2 · Free remedy

API keys in email, documents, or never rotated

an exposed API key is your AI agent, in an attacker's hands, at your expense.

Why underwriters ask about it

an exposed API key is your AI agent, in an attacker's hands, at your expense.

How to fix it

  1. Find every API key (they're in the integrations you listed in R6.4) and move them out of email, notes, and shared docs into a password manager.
  2. Rotate any key that was ever shared loosely, and rotate all keys when someone with access leaves.
  3. Calendar a twice-yearly rotation.

Evidence to keep

rotation dates noted in the inventory.