Civil Code 1798.91.04(b): If a connected device is equipped with a means for authentication outside a local area network, the security feature is deemed reasonable if either (1) the preprogrammed password is unique to each device manufactured, or (2) the device requires a user to generate a new means of authentication before access is granted for the first time.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.