You do have to worry about securing your dev keys, but even here there's room for improvement with M-of-N multisig website updates, where one of signatories can be auditors your DAO hired on-chain (it will make more sense later), notifs from ZProxy to users, and social recovery