The software vendor must identify and document all critical assets within the payment software, including sensitive data, cryptographic keys, authentication mechanisms, and the components that protect them.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.