Regulated entities must enter into written contracts with processors that limit the processor to acting on documented instructions, require equivalent safeguards, prohibit secondary use, and define audit rights and subcontracting controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.