Key security policy
- never store private keys in chat/email
- use passphrases
- rotate keys on team changes
- keep audit list of key holders
Access hardening
- disable password SSH login where possible
- restrict inbound SSH CIDRs
- use least privilege per operator