Answer yes if service credentials used to authenticate to your software, products or services, such as API keys, service account secrets or certificates, are rotated on a defined schedule and can be revoked promptly if compromised or no longer needed. Describe your rotation and revocation processes in the notes section.