Are Heroku Config Vars safe for sensitive information?

heroku

Solution

Heroku config vars are designed to be safe for storing sensitive information. All config vars are stored in an encrypted form and safely stored. These are only decrypted and loaded when booting your app in a dyno itself.

Problem

I overheard on in a passing conversation that ENV (config vars) on Heroku is not the safest place to store sensitive variables. I thought the opposite was true, and my Google-fu is not helping me any here. Any thoughts?

Original source