loadVariables only from my server

As long as the PHP page is not displaying the information. If it’s just pulling into flash, your pretty secure. Unless you use a decompressor.