My CI server is inside an amazon VPC, accessible via an ssh tunnel. Only certain people can access the production VPC and everyone's keys have a strong passphrase ... why trust your CI tool's security when you can rely on much more robust things like SSH?