The vendor should make an initial assessment of each report to decide whether it describes a potential vulnerability in a supported product or service and how urgent it is, the first step of the verification ISO/IEC 30111 7.1.4 a) and e) describes (initial investigation and prioritization), and tell the reporter the outcome.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.