A private key is used for one purpose only, decryption or signing but not both except in transaction-originating POI devices, never encrypts other keys, and when used for remote key distribution serves no other purpose; certificate signing requests are excepted.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.