Cryptographic keys must be stored in PCI-approved cryptographic devices (HSMs) or under equivalent protection, with secret components never appearing in clear-text outside approved cryptographic boundaries.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.