Processing on a controller's behalf must be governed by a contract setting out clear instructions, nature and purpose, data types, duration and each party's rights and obligations, and requiring the processor to impose confidentiality on its personnel, delete or return data at the end of services unless law requires retention, provide information demonstrating compliance, allow and cooperate with reasonable assessments (or commission an independent assessment against an accepted control framework and share the report), and bind subcontractors in writing to the same requirements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.