Commit to publishing identified vulnerabilities as correct and complete CVE records, particularly the CWE field giving the root cause, and publish analysis of past vulnerabilities and measures taken against whole classes; a rising CVE count can reflect better discovery and should not be read as a failure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.