{
  "schema_version": "mentaview.public-module-maturity/v1",
  "assessment_id": "mentaview-m4-minus-objective-review-20260906",
  "assessment_revision": 1,
  "assessed_at": "2026-09-06",
  "public_claim_id": "CLAIM-0042",
  "target_level": "M4-",
  "scope": "internal-laboratory",
  "framework": {
    "label": "Mentaview M4-",
    "display_label": "M4−",
    "non_standard_scale": true,
    "definition": "An implemented module exercised through a supported integration path, with repeatable local test, evaluation, verification and validation evidence, explicit failure tests, and published limitations.",
    "promotion_rule": "Every required local dimension must pass. Missing, indirect or contradictory evidence prevents M4- assignment.",
    "required_dimensions": [
      "contract",
      "implemented-path",
      "supported-integration",
      "repeatable-local-TEVV",
      "transparent-limitations"
    ],
    "external_anchors": [
      {
        "name": "European Commission Technology Readiness Levels",
        "url": "https://ec.europa.eu/research/participants/data/ref/h2020/wp/2014_2015/annexes/h2020-wp1415-annex-g-trl_en.pdf",
        "use": "TRL 4 supplies the laboratory-validation boundary; the Mentaview minus qualifier is deliberately more cautious and is not an official TRL assessment."
      },
      {
        "name": "NIST AI Risk Management Framework 1.0",
        "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10",
        "use": "Supplies the expectation for documented, repeatable TEVV, limitations, risk measurement and separation between development evidence and independent review."
      },
      {
        "name": "NIST Secure Software Development Framework 1.1",
        "url": "https://csrc.nist.gov/pubs/sp/800/218/final",
        "use": "Supplies the expectations for software evidence, provenance, integrity verification and preserved release artifacts."
      }
    ]
  },
  "truth_boundary": {
    "assessor_independent": false,
    "production_qualified": false,
    "customer_accepted": false,
    "independent_assurance": false,
    "certification_claim": false,
    "statement": "This is a repository-based engineering assessment. It demonstrates internal laboratory maturity only and must not be represented as production qualification, customer acceptance, independent assurance, certification or universal performance."
  },
  "publication_policy": {
    "overview_and_module_pages_use_this_record": true,
    "update_on_each_material_progress": true,
    "deploy_on_each_accepted_revision": true,
    "downgrade_on_contradictory_evidence": true
  },
  "latest_verification": {
    "verified_at": "2026-09-06",
    "scope": "counter-review-of-preexisting-m4-minus-modules",
    "module_slugs": [
      "cognitive-engine",
      "document-retrieval",
      "memory",
      "inference-gateway"
    ],
    "targeted_test_total": 511,
    "targeted_test_passed": 511,
    "targeted_test_failed": 0,
    "targeted_test_ignored": 0,
    "public_summary": "511/511 targeted Rust tests passed for the four modules that were already M4-; the seven newly promoted modules remain bound to their module-specific content-addressed evidence registries.",
    "checks": [
      {
        "id": "kernel-library",
        "module_slugs": ["cognitive-engine"],
        "command": "cargo test --locked -p mentaview-kernel --lib",
        "passed": 491,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "retrieval-scoped-index-integrity",
        "module_slugs": ["document-retrieval"],
        "command": "cargo test --locked -p mentaview-retrieval --test scoped_index_integrity",
        "passed": 5,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "memory-fail-closed-conflict-resolution",
        "module_slugs": ["memory"],
        "command": "cargo test --locked -p mentaview-memory --test fail_closed_conflict_resolution",
        "passed": 5,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "gateway-provider-idempotency",
        "module_slugs": ["inference-gateway"],
        "command": "cargo test --locked -p mentaview-connectors --test provider_idempotency_wave11",
        "passed": 4,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "gateway-http-failover-composition",
        "module_slugs": ["inference-gateway"],
        "command": "cargo test --locked -p mentaview-server --test inference_failover_composition",
        "passed": 4,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "cognitive-postgresql-operating-evidence",
        "module_slugs": ["cognitive-engine"],
        "command": "cargo test --locked -p mentaview-server --test cognitive_operating_evidence_http cognitive_evidence_commits_before_publication_fails_closed_and_survives_restart -- --ignored --exact --nocapture",
        "passed": 1,
        "failed": 0,
        "ignored": 0
      },
      {
        "id": "memory-postgresql-erasure-http",
        "module_slugs": ["memory"],
        "command": "cargo test --locked -p mentaview-server --test memory_erasure_http administrative_memory_erasure_is_authorized_idempotent_and_tenant_scoped -- --ignored --exact --nocapture",
        "passed": 1,
        "failed": 0,
        "ignored": 0
      }
    ],
    "static_analysis": {
      "status": "passed",
      "warnings_observed": 0,
      "packages": [
        "mentaview-kernel",
        "mentaview-retrieval",
        "mentaview-memory",
        "mentaview-connectors",
        "mentaview-server"
      ],
      "policy_exceptions": [
        "clippy::too_many_arguments",
        "clippy::type_complexity",
        "clippy::items_after_test_module"
      ]
    },
    "disposable_postgresql": {
      "major_version": 16,
      "tests_passed": 2,
      "container_removed": true,
      "image_removed": true
    }
  },
  "modules": [
    {
      "slug": "cognitive-engine",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The planning contract, bounded runtime path and server-composed evidence boundary are implemented and locally exercised; production service levels and customer-domain operation remain unproven.",
      "dimensions": {
        "contract": ["docs/06-cognitive-kernel/COGNITIVE_EXECUTION_PLAN_CONTRACT_V1.md"],
        "implemented-path": ["crates/kernel/src/runtime/mod.rs"],
        "supported-integration": ["crates/server/tests/cognitive_operating_evidence_http.rs"],
        "repeatable-local-TEVV": ["crates/kernel/src/runtime/answer_pipeline/tests.rs"],
        "transparent-limitations": ["config/qualification/cognitive-engine-m5.json"]
      },
      "open_limits": [
        "No representative operating period across customer domains and heterogeneous live providers.",
        "No production service-level or customer-acceptance evidence.",
        "No independent assurance opinion."
      ]
    },
    {
      "slug": "question-contract",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The question contract is compiled in the supported kernel path and has deterministic multilingual and metamorphic local evidence; the generated blind human review is not complete.",
      "dimensions": {
        "contract": ["docs/05-architecture/QUESTION_CONTRACT_COMPILER_V1.md"],
        "implemented-path": ["crates/question-contract/src/lib.rs"],
        "supported-integration": ["crates/kernel/examples/wave11_question_evidence_review_qualify.rs"],
        "repeatable-local-TEVV": ["crates/question-contract/tests/metamorphic_contract.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence-qac.json"]
      },
      "open_limits": [
        "The 40-case blind human review remains pending.",
        "No broad prospective customer-domain holdout.",
        "No organizationally independent custody or assurance."
      ]
    },
    {
      "slug": "answer-assurance",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "Claim, citation and publication controls execute in the integrated answer path and pass local adversarial checks; semantic entailment and independent human review remain outside the proven boundary.",
      "dimensions": {
        "contract": ["docs/05-architecture/ANSWER_ASSURANCE_MODULE_V1.md"],
        "implemented-path": ["crates/answer/src/lib.rs"],
        "supported-integration": ["crates/kernel/src/runtime/answer_pipeline/answer_assurance.rs"],
        "repeatable-local-TEVV": ["crates/answer/tests/metamorphic_assurance.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence-qac.json"]
      },
      "open_limits": [
        "The 40-case blind human review remains pending.",
        "Lexical and structural assurance does not prove semantic entailment.",
        "No customer-DMS or independent operating evidence."
      ]
    },
    {
      "slug": "confidentiality-boundary",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The fail-closed provider boundary, reproducible Unicode-derived profile and durable local decision evidence are implemented and tested; representative multilingual calibration is absent.",
      "dimensions": {
        "contract": ["docs/05-architecture/CONFIDENTIALITY_BOUNDARY_MODULE_V1.md"],
        "implemented-path": ["crates/confidentiality/src/lib.rs"],
        "supported-integration": ["crates/kernel/src/confidentiality.rs"],
        "repeatable-local-TEVV": ["crates/confidentiality/tests/adversarial_network_credentials.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence-qac.json"]
      },
      "open_limits": [
        "No customer-approved representative multilingual calibration corpus.",
        "Thresholds have not been approved by customer privacy owners.",
        "No legal review or independent operating-effectiveness evidence."
      ]
    },
    {
      "slug": "document-retrieval",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "Typed retrieval, scope isolation and supported kernel/server composition are implemented and locally verified; the evidence does not establish production-scale relevance or latency.",
      "dimensions": {
        "contract": ["docs/15-rag/RETRIEVAL_CONTRACT_V0.md"],
        "implemented-path": ["crates/retrieval/src/lib.rs"],
        "supported-integration": ["crates/kernel/tests/req_mvp_0005_retrieval_boundary.rs"],
        "repeatable-local-TEVV": ["crates/retrieval/tests/scoped_index_integrity.rs"],
        "transparent-limitations": ["config/qualification/document-retrieval-representative-v1.json"]
      },
      "open_limits": [
        "No production-scale asynchronous ingestion campaign.",
        "No representative customer-corpus drift, relevance or latency qualification.",
        "No independent assurance opinion."
      ]
    },
    {
      "slug": "external-research",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "A bounded, disabled-by-default network research path is integrated and locally exercised with adversarial transport checks; live provider operations and staged traffic remain gated.",
      "dimensions": {
        "contract": ["docs/05-architecture/EXTERNAL_RESEARCH_MODULE_V1.md"],
        "implemented-path": ["crates/research/src/pipeline.rs"],
        "supported-integration": ["crates/kernel/tests/external_research_orchestration.rs"],
        "repeatable-local-TEVV": ["crates/research/tests/operating_evidence_runtime.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence.json"]
      },
      "open_limits": [
        "The prospective 500-case release run has not been completed.",
        "Provider terms, inspected egress, monitoring and staged live traffic remain open.",
        "The transport cannot attest every connected-socket and TLS-handshake property."
      ]
    },
    {
      "slug": "memory",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "Scoped memory, conflict handling, restart continuity and authenticated erasure/export paths are locally implemented and exercised; broad adaptive activation is not qualified.",
      "dimensions": {
        "contract": ["docs/08-memory/MEMORY_MODEL_V0.md"],
        "implemented-path": ["crates/memory/src/lib.rs"],
        "supported-integration": ["crates/server/tests/memory_erasure_http.rs"],
        "repeatable-local-TEVV": ["crates/memory/tests/fail_closed_conflict_resolution.rs"],
        "transparent-limitations": ["config/qualification/memory-m5.json"]
      },
      "open_limits": [
        "No equal-context answer-level representative holdout for broad adaptive activation.",
        "Production multi-user isolation, resource budgets and canary evidence remain open.",
        "Customer consent, retention and deletion exercises remain unproven."
      ]
    },
    {
      "slug": "multimodal-ingestion",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The typed ingestion and durable local recovery/purge lifecycles are integrated and failure-tested across bounded profiles; breadth and distributed-operation claims remain explicitly excluded.",
      "dimensions": {
        "contract": ["docs/15-rag/UNIVERSAL_MULTIMODAL_INGESTION_V2.md"],
        "implemented-path": ["crates/multimodal-ingestion/src/universal_execution.rs"],
        "supported-integration": ["crates/server/tests/knowledge_input_operating_evidence_http.rs"],
        "repeatable-local-TEVV": ["crates/multimodal-ingestion/tests/operating_evidence_failure_runtime.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence.json"]
      },
      "open_limits": [
        "Two checksum-pinned real-corpus tests require external assets and are not part of the default replay.",
        "The qualified paths do not cover representative devices, languages, layouts or long meetings.",
        "Managed KMS, remote object storage, distributed leases and accepted diarization remain open."
      ]
    },
    {
      "slug": "inference-gateway",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "Provider-neutral routing, idempotency boundaries and failover/reconciliation controls are composed and locally tested; sustained heterogeneous-provider operation is not proven.",
      "dimensions": {
        "contract": ["docs/14-routing/INFERENCE_MESH_CONTRACT_V0.md"],
        "implemented-path": ["crates/connectors/src/failover.rs"],
        "supported-integration": ["crates/server/tests/inference_failover_composition.rs"],
        "repeatable-local-TEVV": ["crates/connectors/tests/provider_idempotency_wave11.rs"],
        "transparent-limitations": ["config/qualification/inference-gateway-m5.json"]
      },
      "open_limits": [
        "No sustained target-host run across heterogeneous live providers.",
        "Provider-declared idempotency and invoice-external reconciliation are not broadly qualified.",
        "No production service-level or customer-acceptance evidence."
      ]
    },
    {
      "slug": "edge-oem-runtime",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The offline runtime, signed install chain, anti-rollback state and TPM transcript boundary are executable and locally failure-tested; physical-device claims remain false.",
      "dimensions": {
        "contract": ["docs/05-architecture/EMBEDDED_AUTONOMOUS_PROFILE_V1.md"],
        "implemented-path": ["crates/edge/src/fleet.rs"],
        "supported-integration": ["crates/edge/tests/release_install_cli.rs"],
        "repeatable-local-TEVV": ["crates/edge/src/tpm2.rs"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence-edge-evaluation.json"]
      },
      "open_limits": [
        "No physical TPM execution or controlled power-cut campaign.",
        "No OEM target workload, fleet rollout or native packaging qualification.",
        "No measured target-device RAM, storage, latency or energy envelope."
      ]
    },
    {
      "slug": "evaluation-kit",
      "level": "M4-",
      "decision": "pass",
      "confidence": "moderate",
      "review_summary": "The evaluation, custody, signature and reproduction tooling is executable and adversarially tested locally; same-process hostility and independent clean-room reproduction remain outside the proven boundary.",
      "dimensions": {
        "contract": ["docs/40-release/MENTAVIEW_M5_EVIDENCE_PACK_PROTOCOL_2026-09-04.md"],
        "implemented-path": ["tools/evaluation/module_m5_evidence_pack.py"],
        "supported-integration": ["tools/evaluation/run_book_evaluation_autopilot.py"],
        "repeatable-local-TEVV": ["tools/evaluation/test_module_m5_evidence_pack.py"],
        "transparent-limitations": ["config/compliance/module-m4-minus-local-evidence-edge-evaluation.json"]
      },
      "open_limits": [
        "A hostile actor in the same Python interpreter can bypass process-local controls.",
        "No organizationally independent identities, human gold or licensed-corpus custody campaign.",
        "No signed clean-room multi-host reproduction or customer acceptance."
      ]
    }
  ],
  "progress_history": [
    {
      "revision": 1,
      "date": "2026-09-06",
      "event": "Initial objective M4- review prepared for public publication.",
      "module_levels_changed": [
        "question-contract",
        "answer-assurance",
        "confidentiality-boundary",
        "external-research",
        "multimodal-ingestion",
        "edge-oem-runtime",
        "evaluation-kit"
      ]
    }
  ]
}
