Keep your project API key in a secret store. Never put it in chat, code you commit, or a URL. You
only see it once. Making a new key turns off the old one.
Your coding agent's access is separate from the API key. Remove it from
Agent connections without changing the key.
Use Langfuse keys made just for Kensa. Langfuse keys can do more than read. Kensa stores them
encrypted and never shows them again.
If some data must never reach Kensa, remove it before it leaves your systems.
Trace data
Kensa removes all PII and sensitive data from traces before processing them. It only stores the redacted traces.
Connecting GitHub is optional. Kensa uses it only to read your code when drafting your agent's job and defining what good looks like.