TIPA provides an affirmative defence when the controller's privacy programme reasonably conforms to the NIST Privacy Framework, with documented mappings, control implementation, and independent validation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.