At LoA4 there is very high confidence in the identity, for high risk; it is LoA3 plus in-person identity proofing for human entities and tamper-resistant hardware devices for the storage of all secret or private cryptographic keys, and all PII and other sensitive data in authentication protocols shall be cryptographically protected in transit and at rest; it suits services where authentication failure risks harm or distress or criminal liability for the responsible party and approval of transactions with high risk of financial loss; digital certificates (X.509, card-verifier certificates) may authenticate NPEs such as smartphones or smart meters.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.