will is probably referring to version control/change tracking, and not to "security".
Regardless their point was poorly explained/explored.
I use a sftp atom plugin to workin on/save to my dev server and just use ssh to do git/etc right on the server. I don't see how this workflow is very different than working locally and using a command prompt for all of your tools.