Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The guide includes concrete API and SMTP examples for sending legally significant KEP messages, including placeholders for bearer tokens and passwords, but provides no security guidance on secret storage, transport validation, authorization controls, audit logging, or the legal consequences of automated sending. In this context, readers may copy the examples into production and handle sensitive credentials or send binding legal notices without adequate safeguards, increasing the risk of credential exposure, unauthorized transmission, and compliance failures.
