--- since: 1.0.6 --- # Privacy and Security ## Repository secrets Do not place production credentials in the CLI repository. The CLI's optional machine-local secret source is: ```text ~/.dplay/.secrets ``` ## Local TLS Certificates under: ```text ~/.dplay/ssl/ ``` are local development certificates. They should not be reused as production TLS credentials. ## Host application execution The CLI invokes host application scripts and management commands as subprocesses. Review the target repository and configuration before granting elevated permissions to certificate-trust operations. ## `system reset` `dplay system reset` executes: ```bash redis-cli flushall ``` Therefore Redis data is deleted from the Redis instance addressed by the local CLI configuration/environment. Use it only for a development Redis instance. ## Process termination The current process manager uses forceful `pkill -9` patterns to terminate development Celery/Django processes. This can terminate matching processes that were not started by the current CLI session if they satisfy the same process pattern. Keep the CLI scoped to development machines.