How can you prevent code from creating a handle in a new place?

You can limit access to your db credentials. But other code can still launch missiles etc.