Devices are physically protected from the manufacturer to key insertion and deployment by a trusted courier with secure storage, by physically secure trackable packaging such as pre-serialised counterfeit-resistant tamper-evident packaging, by a device-unique transport-protection token that the key-insertion SCD verifies before overwriting, or by the device authenticating itself to the SCD.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.