Your product asks
A request arrives with its authorized user, tenant, conversation and data context.
Provider-neutral cognitive runtime
Mentaview chooses the smallest sufficient path, connects evidence to answers, and keeps models, memory, data and deployment under explicit control.
v0.1.0 controlled pilot. Source and macOS arm64 binary access are available by separate agreement under an all-rights-reserved, no-license-granted notice. Capabilities remain labelled as implemented, controlled pilot, canary or roadmap; there is no certification or general-availability claim.
Product scope
The decisions a model does not own: permissions, evidence obligations, capability budgets, provider policy and safe refusal.
Define the role FOR PRODUCT, BUSINESS AND AI LEADERSThe problem Mentaview solves, the outcomes it targets, where it fits and how to evaluate it without starting with a platform migration.
Read the solution FOR ARCHITECTS, ENGINEERS AND SECURITY TEAMSRust runtime boundaries, direct and HTTP access, API routes, request lifecycle, security, deployment and measured performance.
Inspect the technology01
What is it for?
Mentaview sits between your application and the AI capabilities it may use. For every request, it decides what is actually necessary, authorizes that path and returns a result your product can explain.
A request arrives with its authorized user, tenant, conversation and data context.
Answer directly, remember, retrieve private documents, research current sources, use an approved model — or stop.
An answer with evidence, visible gaps, route trace and explicit failure or abstention behavior.
02 / Why it matters
Mentaview is useful when it improves one or more measurable dimensions of an AI workload. If it does not beat the simplest valid path, it should step aside.
Add memory, private evidence, fresh research or stronger assurance only when the request needs it.
Avoid unnecessary retrieval, tools and model calls so simple work keeps the simplest valid path.
Make provider choice, data scope, egress, retention, budgets and failure behavior explicit.
Run in-process, on your infrastructure, at the edge or through a managed profile without changing the cognitive contract.
Keep claims connected to admissible evidence, expose missing support and abstain when a safe answer is not possible.
Preserve useful state, retrieval, audit and deletion paths even when a model or the network is unavailable.
03 / Product system
Each module owns a provider-neutral contract, an evidence gate and a failure boundary. Complexity stays replaceable.
Use complexity only when it earns its place.
Explore moduleTurn a question into observable answer obligations.
Explore modulePrefer a safe partial answer to a polished unsupported one.
Explore moduleKeep obvious confidential identifiers out of protected model calls — and restore them after validation.
Explore moduleMake private and oversized corpora answerable with provenance intact.
Explore moduleSearch only when authorized local evidence is insufficient.
Explore module04 / Access & technology
Embed Mentaview for the shortest path, call it over an authenticated network boundary, or run a local profile. Presentation transports never get to redefine routing, memory or evidence policy.
Native servers, appliances and performance-sensitive products can use the unpublished Rust SDK v1 over injected in-process services. A separate injectable synchronous transport contract lets a host compose bounded network exchanges without making the SDK itself an HTTP client.
PaaS, on-premises and remote clients use versioned /v1 operations with tenant-aware API keys, normalized errors, request IDs and explicit provider policy.
Operators can exercise local and edge profiles from a command line, with separately installed model packs and no automatic download, discovery or network access.
A web or mobile client may add streaming or WebSocket presentation above the same API. That transport stays outside cognitive policy and is not yet a qualified public SDK.
Current access boundary: the in-process Rust SDK v1, its injected host-owned network-transport contract and the controlled-pilot HTTP server exist today. The Rust crate remains unpublished; no real HTTP/TLS/DNS path has been qualified through the SDK contract, and registry distribution, compatibility history, language/mobile bindings and streaming/socket clients remain promotion gates.
Inspect the complete technical architecture05 / Deployment freedom
The orchestrator and the inference location are independent decisions. Start without a model, add only what policy allows.
Add governed cognition through authenticated APIs while keeping inference pools explicit and replaceable.
Managed headless cognitive orchestrationA turnkey service for teams that want Mentaview-operated lifecycle, quotas, support and control plane.
Complete managed product experienceKeep data, credentials and inference inside the customer's server, LAN or VPC boundary.
Customer-operated private runtimeRun state, ingestion, retrieval and policy locally; add verified on-device inference only when the host chooses it.
Local cognition with no mandatory network06 / Performance
Mentaview measures answer quality, latency, calls, resources, isolation and recovery against the simplest valid baseline. These are selected internal results on stated profiles — not production SLAs or universal claims.
Sealed multilingual Wave 11 machine holdout; zero orphan claims, critical false-completes or extra model calls; 40 blind human reviews remain pending
Completed with three recorded restarts on the tested path
Semantic, provenance and citations; zero orphan citations or research budget failures
Sealed synthetic BM25 holdout; zero wrong-document top-1 results and zero scope leaks
Three separately executed prospective suites on frozen profiles
On one short-context internal matrix, direct inference scored 100% in 1.752 s while Mentaview scored 95.71% in 6.113 s. The correct product decision is not to hide that result — it is to make the direct path win.
07 / Assurance readiness
Mentaview has structured an integrated assurance workspace across eight routes, machine-readable scope, cross-framework control mapping, evidence manifests and human action plans.
Truth boundary: templates, source controls and readiness tooling are not operating evidence, an audit report or a certificate. Submission and public-claim gates remain closed.
Examine the assurance program08 / Frontier, without fiction
Sandboxed tools, explicit approvals, checkpoints, resumable tasks and failure-directed verification must earn promotion on prospective benchmarks.
Workspace identity, immutable code evidence, budgets and permissions are defined. Operational search, patch, terminal and Git tools remain future adapters.
09 / Our vision
Teams should be able to benefit from better models and richer capabilities without surrendering their data control, architectural freedom or the ability to understand why a system acted.
AI systems that remain useful, inspectable and sovereign across models, providers and deployment boundaries.
Build the cognitive layer that chooses the smallest sufficient path and turns evidence into accountable action.
Capture the value of advanced AI without surrendering data control, architectural freedom or intellectual honesty.
A deliberate next step
We will map the smallest useful Mentaview profile, the evidence needed to justify it and the boundaries that must stay closed.