review:
  upstream_repository: https://github.com/agenticfabriq/mnemiq
  reviewed_commit: a08fe859c2ee38eb95f3239ee71a11e8f47b75ba
  reviewed_on: 2026-09-15
  product_version: 0.1.0.dev0
  license: Apache-2.0
claims:
  - id: MN-01
    control: AU-01
    status: implemented
    evidence: src/mnemiq/authz; README permissions-before-retrieval description
    limit: Correct deployment policy and identity configuration remain operator responsibilities.
  - id: MN-02
    control: AU-02
    status: implemented
    evidence: src/mnemiq/sql/authz_guard.py; src/mnemiq/sql/decide.py
    limit: Source-native permissions are still required as defense in depth.
  - id: MN-03
    control: QS-01
    status: implemented
    evidence: src/mnemiq/sql/guard.py; src/mnemiq/sql/decide_write.py
    limit: Read-plane safety also depends on source behavior, including callable functions and views.
  - id: MN-04
    control: SE-01
    status: supported
    evidence: src/mnemiq/enrichment/certified.py; src/mnemiq/enrichment/dictionary.py
    limit: Mnemiq can represent certified definitions; the operator must supply and govern them.
  - id: MN-05
    control: VE-02
    status: implemented
    evidence: src/mnemiq/verify; tests/test_verify_unavailable.py
    limit: Verification mode and risk-tier policy are deployment choices.
  - id: MN-06
    control: RF-01
    status: implemented_and_evaluated
    evidence: refusal behavior, evaluation harness and public benchmark artifacts in the upstream repository
    limit: Published benchmark results do not predict performance on another organization's schema.
  - id: MN-07
    control: LN-01
    status: supported
    evidence: trace fields for SQL, tables, lineage completeness, enrichment version and timing
    limit: Retention, tamper evidence and enterprise audit integration sit outside the open engine.
  - id: MN-08
    control: QS-02
    status: deployment_responsibility
    evidence: docs/oracle-deployment.md and supported-source configuration
    limit: A library cannot independently guarantee that the configured database principal is least privileged.
