--- type: work-item project: fidelity status: backlog ticket: PDIAP-11961 title: "Remediation of Exposed Secrets in XFlow iOS SDK - Request for Rotation/Invalidation" systems: [xflowsdk] workstreams: [security, backlog-triage] people: [jeff-dewitte] related: [pdiap-11962] updated: 2026-05-05 tags: - work-item - fidelity - security --- # PDIAP-11961 - Remediation of Exposed Secrets in XFlow iOS SDK - Request for Rotation/Invalidation ## Status - Backlog item; not assigned yet. - Jeff relayed that this is not a priority yet, but asked David to keep the details noted for future reference. --- ## Context - Related to the remaining Google API Key alerts not included in the previous `PDIAP-11962` closure. - If key rotation or invalidation is required, David/XFlow likely needs backend support or clarification because Google API Key rotation is not owned directly by the XFlow iOS side. --- ## Historical Slack Context - October 2025 Slack context describes `PDIAP-11961` as the request for rotation/invalidation of active exposed Google API keys. - The active Google API keys were documented as still valid/in use by the service, so they were intentionally separated from inactive-secret closure evidence. - `PDIAP-11962` was created as the second-phase closure story to run after `PDIAP-11961` invalidation/rotation work completed. - Earlier investigation noted that the API key appeared in a service response and that GitHub was flagging the old commit where the key had been hard-coded and later removed.