What is required for stages, without credentials, to limit data exfiltration after a storage Integration and associated stages are created?