02 / Technology

One cognitive contract, from in-process Rust to authenticated HTTP

Explore Mentaview's Rust architecture, direct and authenticated HTTP access, API lifecycle, security boundaries, deployment profiles and measured performance.

The Rust core, unpublished in-process SDK v1 and injected host-owned network-transport contract are implemented as a controlled pilot. The HTTP server is also a controlled pilot. The SDK contract has no qualified real network execution; registry distribution, compatibility history, language SDKs and streaming clients remain roadmap work.

01

System architecture

The presentation layer can change. The cognitive and policy contract does not.

Mentaview separates how a host reaches the system from how a request is authorized, planned, executed, verified and observed. That keeps interface transports replaceable and prevents a chat client from becoming the policy engine.

02

Access surfaces

Choose the boundary that matches the host, not the one that changes product behavior.

The same domain and application contracts sit behind each qualified access path. Status labels describe current maturity, not a promise that every distribution is ready today.

01Controlled pilot

Rust SDK v1 and direct services

The shortest path for native servers, appliances and performance-sensitive hosts. An unpublished bounded v1 facade reaches injected application and kernel contracts directly, and a separate synchronous transport contract lets the host compose bounded network exchanges without making the SDK an HTTP client.

02Controlled pilot

Authenticated HTTP /v1 API

Remote products use versioned JSON operations, tenant-aware credentials, normalized errors, correlation IDs, health probes and Prometheus-compatible metrics.

03Canary

CLI and edge compositions

Operators can run explicit local profiles, inspect capability availability and add separately installed inference or retrieval packs without automatic discovery or download.

04Roadmap

Streaming and WebSocket client layer

Future language and network clients may expose token and lifecycle events over streaming transports. They will present the existing contract, not own cognition, memory, authorization or evidence policy.

03

Request lifecycle

A request is governed before a model is considered.

Inference is one optional step in a larger lifecycle. Core state, control and data capabilities remain valid when no external provider is configured.

  1. 01

    Authenticate

    Resolve the tenant-aware principal, request ID and authorized scope before application work begins.

  2. 02

    Compile

    Turn content and requested profile into provider-neutral intent, answer obligations and resource budgets.

  3. 03

    Authorize

    Intersect possible capabilities with data, egress, provider and deployment policy.

  4. 04

    Execute

    Use direct handling or the minimum justified combination of memory, retrieval, research and inference.

  5. 05

    Assure

    Check requested-facet coverage, evidence admissibility, citation fidelity and remaining gaps.

  6. 06

    Persist and observe

    Store authorized state through journaled required effects, expose bounded recovery state, emit audit, metrics and normalized non-invoice usage evidence, and return an explicit outcome or error.

04

HTTP surface

A small, versioned API for conversations, evidence and operations.

The current network surface uses authenticated JSON operations with caller-supplied or generated request IDs, input validation and normalized error responses. It is a controlled-pilot interface, not yet a general-availability SDK commitment.

Runtime

Controlled pilot
  • POST/v1/conversations/{conversation_id}/turns

    Run a governed conversational turn.

  • POST/v1/conversations/{conversation_id}/retrieval

    Retrieve authorized private evidence for a conversation.

  • GET/v1/conversations/{conversation_id}/executions/{execution_id}/recovery

    Read bounded tenant-scoped reconciliation state; manual recovery remains explicit for indeterminate dispatch.

  • GET/v1/conversations/{conversation_id}/executions/{execution_id}/commercial-usage

    Read tenant-scoped normalized provider usage evidence; the response is explicitly non-invoice and non-billing-authoritative.

  • GET/v1/conversations/{conversation_id}/state

    Read the scoped conversation state.

  • GET/v1/conversations/{conversation_id}/memories

    List memories visible in the active scope.

Knowledge and learning

Controlled pilot
  • POST/v1/knowledge/sources

    Register a knowledge source under explicit policy.

  • POST/v1/knowledge/files

    Ingest an authorized file through the document boundary.

  • POST/v1/conversations/{conversation_id}/executions/{execution_id}/feedback

    Attach feedback to one resolved execution.

Operations

Implemented
  • GET/health/live

    Report process liveness.

  • GET/health/ready

    Report dependency and readiness state.

  • GET/metrics

    Expose operational metrics for the deployment.

Authentication

Protected operations require a tenant-aware API credential. Health and metrics routes support deployment operations.

Conversation input

Turns accept content plus bounded cognitive, task and research preferences. Server policy remains authoritative.

Errors and correlation

Failures use normalized envelopes. A request ID is propagated or generated so the execution can be traced without relying on raw prompt logs.

05

Rust runtime boundaries

Twenty-eight workspace members, separated by responsibility rather than deployment fashion.

The workspace isolates stable contracts, cognitive decisions, capability modules, adapters and application surfaces. A module can be tested or packaged without requiring the entire system to become one opaque service.

01

Domain and API

Stable identifiers, requests, outcomes and normalized failures. No provider transport or storage detail belongs here.

02

Kernel

Intent, planning, capability budgets, policy and publication decisions. This is the provider-neutral cognitive control plane.

03

Cognitive modules

Question contract, memory, retrieval, research, evidence firewall and ingestion own separate, testable responsibilities.

04

Adapters

Inference, embeddings, stores and external transports implement contracts without becoming product policy.

05

Application surfaces

Direct Rust calls, HTTP server, CLI and edge compositions expose the same underlying behavior for different hosts.

06

Evidence estate

Frozen holdouts, replay inputs, promotion gates and failure tests decide whether a capability can move between maturity levels.

Inspect every product module and its boundary
06

Security and sovereignty

No model and no network are valid operating states.

Core operation does not require an automatically loaded model or an undeclared external service. When generative inference is necessary but unavailable or unauthorized, the system reports that boundary explicitly.

01

Identity and scope

Tenant-aware API keys and scoped conversation state. PostgreSQL row-level security supports tenant isolation on the network profile.

02

Egress and providers

No provider is a valid configuration. Generative work returns an explicit inference-required outcome when no authorized endpoint exists.

03

Model supply

No automatic model download, discovery or invocation. Local packs are separately installed, verified and selected by the host.

04

Confidentiality

Deployment-aware pseudonymization can protect recognized values before remote inference, then validate and restore them inside the originating scope.

05

Failure behavior

Budgets, bounded repair, normalized errors and abstention prevent retry loops or silent fallback from becoming policy.

06

Observability

Correlation IDs, health, metrics and aggregate traces expose route behavior without making raw private content the default telemetry surface.

Review assurance scope and open evidence gaps
07

Deployment profiles

Orchestration location and inference location are separate choices.

Each distribution profile has its own readiness boundary. Existing contracts can be shared while installers, Rust SDK distribution, compatibility evidence, language bindings, commercial controls and device qualification advance independently.

Managed headless cognitive orchestration

PaaS

Controlled pilot

Add governed cognition through authenticated APIs while keeping inference pools explicit and replaceable.

Available now
Tenant-aware HTTP runtime, PostgreSQL state, policy, routing, shared admission, turn-effect reconciliation and tenant-scoped normalized commercial-usage evidence with non-invoice readback.
Promotion gate
Server-wide adoption of provider idempotency, durable multi-instance conflict coordination, operator resolution for indeterminate dispatch, external tariff and invoice systems, high-throughput qualification, heterogeneous endpoints, SSO/SCIM and production SLOs.
Complete managed product experience

SaaS

Roadmap

A turnkey service for teams that want Mentaview-operated lifecycle, quotas, support and control plane.

Available now
Reference Kubernetes manifests and the shared server runtime exist.
Promotion gate
Commercial control plane, tenant self-service, support SLOs, DR evidence and production qualification.
Customer-operated private runtime

On-premises

Controlled pilot

Keep data, credentials and inference inside the customer's server, LAN or VPC boundary.

Available now
Core-only Compose, explicit optional inference, tenant auth, PostgreSQL RLS, atomic logical restore and a sealed physical backup/WAL exercise recovered to one measured LSN.
Promotion gate
Installer and upgrade qualification, encrypted off-site retention, scheduled recovery monitoring, production RPO/RTO, application reconciliation and full egress allowlisting.
Local cognition with no mandatory network

Embedded / Edge

Canary

Run state, ingestion, retrieval and policy locally; add verified on-device inference only when the host chooses it.

Available now
Network-denied core-only restart plus a sealed content-addressed offline update and one-time device/manifest-bound rollback with exact state handoff.
Promotion gate
Physical-device evidence, hardware-rooted signing and identity, fleet rollout/revocation, power-loss, storage, RAM, latency, energy and packaging qualification.
Linked runtime for devices and appliances

OEM

Roadmap

Embed a policy-governed cognitive layer behind host callbacks, selected accelerators and product-specific constraints.

Available now
Provider-neutral Rust traits, direct API boundaries and endpoint dispatcher.
Promotion gate
Stable ABI, integrator kit, compatibility matrix, signed packs and per-SKU assurance.
Build Mentaview into another product

SDK / Headless

Controlled pilot

Consume cognition in-process for performance or through HTTP for remote clients without importing provider policy into the UI.

Available now
An unpublished Rust SDK v1 facade provides bounded in-process contracts plus a 14-test injectable synchronous network-transport contract with host-owned authentication references; it does not implement or qualify real HTTP.
Promotion gate
Real HTTP/TLS/DNS/egress qualification, timeout and cancellation enforcement, registry distribution, compatibility history, language bindings, streaming transports and stable ABI decisions.
Compare deployment envelopes in detail
08

Performance discipline

Performance means quality per call under the required boundary.

Latency alone is incomplete, and quality without resource or failure accounting is equally incomplete. Evaluations compare correctness, coverage, p95 latency, calls, abstention, restart behavior, isolation and target-hardware constraints.

Internal holdout40 / 40

runtime evidence cases

Sealed multilingual Wave 11 machine holdout; zero orphan claims, critical false-completes or extra model calls; 40 blind human reviews remain pending

Internal validation1,000

turn endurance journey

Completed with three recorded restarts on the tested path

Production candidate36 / 36

research answer contracts

Semantic, provenance and citations; zero orphan citations or research budget failures

Internal holdout48 / 48

root-intent recall@5

Sealed synthetic BM25 holdout; zero wrong-document top-1 results and zero scope leaks

Internal holdout174 / 174

sealed firewall assertions

Three separately executed prospective suites on frozen profiles

Measurement boundary: these figures describe historical internal or canary profiles on named workloads. They do not constitute a production SLA, capacity commitment or claim that orchestration always outperforms direct inference.

Read the evidence record and negative result
09

Integration path

Integrate the contract before expanding the capability surface.

A useful technical evaluation is staged so identity, errors, observability and deletion can be verified before adding private corpora or model providers.

  1. 01

    Select the host boundary

    Choose direct Rust or the HTTP pilot and define the exact deployment profile.

  2. 02

    Prove the core-only path

    Validate identity, conversation state, health, metrics, normalized errors and an inference-required outcome with no provider.

  3. 03

    Add one evidence source

    Ingest a bounded corpus, test retrieval provenance and verify scope, export and deletion behavior.

  4. 04

    Authorize one inference class

    Register a local, controlled-private or public endpoint with explicit egress and confidentiality policy.

  5. 05

    Freeze acceptance gates

    Compare the complete path with the simplest valid baseline on representative held-out work.

A bounded next step

Review the architecture against your real boundary.

Bring the host application, data topology, provider class, target hardware and acceptance envelope. The first output should be an explicit integration and evidence contract.

Define an evaluationReturn to the product value