So you're suggesting GitHub should determine the total "average" license of a private repo and determine if your fork is indeed valid or not, before revoking access.
I was tired of building bespoke static HTML sites and having to decide if I wanted to use GatsbyJS or just hand code all of the HTML. I decided to build a tool to solve my problem!
Do you store your API keys and other sensitive data with a site that doesn't even have a page discussing their encryption or security practices? Their privacy policy mentions they secure data with SSL protocol...
Who has access to each client's database? Is it audited? Is it encrypted at rest? I'm sure it is, but Config.ly would be wise to add this information to avoid fears.
Also you can store encrypted secrets in Git just fine, there are a number of methods to do so very safely.