Initially we've been focused on giving users control and transparency. We need to extend this to employers.
One quick idea that we'd love your feedback on: a .kiteignore file that can exclude Kite from responding to files that match a certain pattern (e.g. "secrets.py"). Presumably an employer could put a "[^.]*" in a repo-level .kiteignore file, and anyone working with that repo would have to explicitly delete that file to use Kite with it.
We'd love to hear any other ideas folks might have as well!