What's the goal?
There are extra steps you can take to try to improve the security against malware, but using environment variables instead of hard coding isn't really intended for that, I don't think.
It's just to stop accidental leaks with stuff like git and other code sharing.
I'm not going to argue business needs here. I don't have balance sheets.
I do respect coming out and directly acknowledging that the community might not be happy with pricing instead of just straight up ignoring backlash or hand waving it away.