An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.