Keeping credentials in a vault rather than in code or config, injecting them at runtime, and replacing them on a schedule or after exposure.
You have done this if
You moved API keys from environment files into Key Vault and set a 90-day rotation.
Say it in a review
No secret lives in the repo or the prompt; keys come from the vault at runtime and rotate quarterly.
On the AI Application map Secrets