Per CISA Secure by Design Principle 2: transparency. Requirements include (a) publish CVE disclosures including root cause + impact + (b) accept responsibility for product security flaws + (c) transparency on Memory Safety transition + (d) transparency on Vulnerability Disclosure Policy + (e) maintain Secure Development Lifecycle transparency.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.