I don't see any mention of a critical remediation step - ensuring there are no credentials in their documentation.
Notion being a SaaS, there is always a risk of some misconfiguration or breach leaking the information from it.
Notion being a SaaS, there is always a risk of some misconfiguration or breach leaking the information from it.
There is no good reason to keep secrets in clear text in a doc/code repo/knowledge base.