Public exposure often starts with deployment artifacts rather than application code. Backup archives, source-control directories, environment files and debug pages can disclose sensitive information.
Review the deployment boundary
Keep secrets outside the public document root and deny access to development artifacts.