That information is long lived (unlike tokens which expire) and you need to use the real value (unlike the hash of a password). Are there resources/books which cover the (many) best practices to keep that information safe?
Things like: separate database/microservice, separate vpc?, encrypt the database, filter those fields from logs, etc etc etc.
Is a service like aws lambda actually more secure then using a paas (heroku/fly/render) vs ECS (where there might be slower turn around times to actually bump/patch CVEs than the aws lambda team would take?).