Per OWASP ASVS V8 + V8.3: implement data protection. Requirements include (a) classify sensitive data + apply appropriate protection per classification + (b) implement encryption at rest + in transit + appropriate to classification + (c) implement data minimisation + retention limits + secure deletion + (d) protect data in memory + during processing + (e) protect against caching + browser history exposure of sensitive data + (f) protect against device storage exposure + (g) implement privacy controls aligned to applicable regulation (GDPR + CCPA + APPI + similar) including data subject rights.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.