Storage protects personal data at rest via encryption, key management, access segmentation, deniable/searchable encryption where required, and tamper evidence; storage architecture decisions (e.g. centralisation, replication) are part of the privacy design.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.