Per OWASP MASVS v2 MASVS-CRYPTO: correct use of cryptography in mobile apps. Requirements include (a) use industry-vetted cryptographic primitives + libraries + parameter choices appropriate to risk + (b) avoid weak + deprecated algorithms + custom cryptography + (c) use platform-provided cryptographic APIs over rolling own + (d) implement secure key management using hardware-backed key storage (Android Keystore + iOS Secure Enclave) where available + (e) maintain key lifecycle including generation + rotation + revocation + destruction + (f) maintain crypto-agility for migration when algorithms or parameters become broken + (g) protect cryptographic material in memory and during processing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.