Keys must be loaded into POI devices and HSMs in a secure manner that prevents disclosure or substitution, with appropriate dual control, witness verification, and detailed logging.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.