Selection of the most applicable PET should be driven by the data protection requirement (the principle being implemented), the threat model, the data utility needed and the operational/cost constraints, with multiple PETs typically combined to achieve the goal.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.