Prevent secrets, API tokens, private keys, and credentials from being baked into container images at build time. Use a runtime secrets manager and scan images for secrets before they are pushed to the registry.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.