The decryption environment where account data is converted from ciphertext to plaintext must be logically isolated, hardened, and protected by strong access controls compliant with PCI DSS.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.