Phil Scott gives an excellent rundown on why your application shouldn't use the SA account to log in with.
This link might serve you well as a handy page slap next time you see "sa" in a connection string.
Not only that, but very cool use of a Spinal Tap reference in the blog. Way to go Phil!