Processing by a processor must be governed by a contract between the controller and the processor that sets out instructions for processing, nature and purpose of processing, type of data, duration of processing, rights and obligations of both parties, confidentiality duty, deletion or return of data at end of provision, audit cooperation and use of subcontractors only with controller authorization under a written contract that flows down the obligations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.