Cryptographic key erasure : ServerConfigurationModel.java
The data members of the class consisting in arrays containing secrets should be overwritten when a instance of this class is not used anymore.
About the field secretCaptchaKey : may be this data will end up finally in a string (for its transmission for example) but it should be clear that storing a secret in a string implies that this secret will remain in memory for an undetermined length of time.