This is a good point @lastmjs. You can assume that source code in a Graphcool Function is kept safe. Our execution engine is using the concept of containers to separate functions. For performance reasons all functions within a project are executed in the same container, but there is no way for functions in different projects to interact with each other.
Even though it is safe to store secrets in your Graphcool Functions, I think it would be valuable for Graphcool to provide a centrally managed store for environment variables. Could you open a feature request for this?
If you decide you need to manage your secrets with environment variables, I would encourage you to look into the Serverless Framework and AWS lambda. It allows you to easily deploy a lambda function with injected environment variables that you can hook into your Graphcool project as a webhook.