> For the complete documentation index, see [llms.txt](https://docs.tryterra.co/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tryterra.co/faq/help-topics/data-api-sdk/account-config-environments-and-going-live/vapt-security-findings-on-sdk.md).

# How do I handle VAPT findings against the SDK?

Common VAPT findings on the SDK, and how to handle each:

* **Hardcoded secrets:** usually the API key / dev ID passed during init from your own code. **Keep the API key on your backend, not in the client.**
* **`allowBackup=true` in the SDK module:** override it by setting `android:allowBackup=false` with `tools:replace` in your app manifest.
* **Flagged cipher modes:** these belong to a deprecated, inactive feature.
* **V2/V3 certificate signing:** controlled by your app's `signingConfigs`, not the SDK.
