# Security policy DSH Design Mode keeps provider credentials on the Host side and resolves them through the DSH credential provider only when a job starts. ## Never include in an issue or commit - `OPENAI_API_KEY`, `FAL_KEY`, or any other provider token - `.env` files - `.dsh/design-mode` session directories - private source images or exported workspace archives - terminal logs that contain request headers or credentials ## Reporting a vulnerability Please open a GitHub security advisory for the repository instead of filing a public issue. Include a minimal reproduction that uses placeholder credentials and synthetic assets.