As builder content API provides option "includeUnpublished", I consider this a security risk as anyone can reach Builder API (API key of space is publicly visible) and reach for data that are not publicly available yet (drafts of product launch pages, content scheduled for some date).
This can leak important information too soon.
Adding option to accept "includeUnpublished" option only with private key within the request would help. It could be simple space setting or per-model setting.
This feature currently exists in Builder, and can be enabled via a space's settings: https://www.builder.io/c/docs/content-api#published-ne