For our API keys and stuff we just stored them in ...
# suitescript
b
For our API keys and stuff we just stored them in encrypted fields in NetSuite that only administrators had access to.