Sensitive authentication data must not be stored after authorization. If retained temporarily during authorization, it must be protected with strong cryptography and securely deleted immediately after use.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.