Your LightDrive address book belongs to your account. It is not a public profile or a shared company directory.
CardDAV clients authenticate before they can read or change contacts. Use HTTPS, keep certificate checking enabled, and give each long-lived client its own password. Create a Contacts-only password under Contacts → Mobile & app connections, or use an Email & contacts password from Settings → Security → App & device access when one app needs both services. The main Vault password, Vault app passwords, and Email-only passwords do not authenticate to CardDAV.
A contact can contain sensitive information such as home addresses, phone numbers, birthdays, and notes. Add only the information you need, protect every synchronized device with a screen lock, and review an app’s privacy practices before granting it contacts access.