Most startups treat SSH access as a setup-and-forget task. A developer generates a key pair during onboarding, connects to the production server, and never thinks about it again. No one audits which keys exist on which machines. No one tracks who still has access after leaving the company. No one asks what would happen if a single leaked private key gave an attacker root access to every production system.
This is not a hypothetical scenario. It is the default state of credential management in the