Silver criterion crypto_credential_agility (MUST; group Security, Use basic good cryptographic practices). Criterion text: The project MUST support storing authentication credentials (such as passwords and dynamic tokens) and private cryptographic keys in files that are separate from other information (such as configuration files, databases, and logs), and permit users to update and replace them without code recompilation. If the project never processes authentication credentials and private cryptographic keys, select "not applicable" (N/A).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.