vendor told me they were going to send API credentials in a “secure document”
It was just a regular word document, but the credentials were in white text so you couldn’t see them without either highlighting or changing the font color
have advised them to add dark mode to their threat model