amu-pgvector
Python client for amu-pgvector: a reference implementation of Lineage-Aware Memory Governance (Sangaraju & Vissa, IEEE Access, 10.1109/ACCESS.2026.3730363) on PostgreSQL + pgvector.
An agent may reuse a cached analytical result only if every sensitive
column touched by that result's derivation is in the requester's
permitted set: S(a) ⊆ P(d). Postgres enforces this itself through row-
level security — it is not a filter this client has to remember to add.
Full project docs, the SQL schema, benchmarks, and the LangChain/MCP integrations live in the main repository: https://github.com/sangaraju1988/amu-pgvector
Install
pip install amu-pgvector
Extras:
pip install amu-pgvector[mcp] # adds the amu-pgvector-mcp MCP server console script
pip install amu-pgvector[st] # adds sentence-transformers for real embeddings
This client talks to a Postgres database that already has the schema
installed — see
sql/amu_pgvector.sql
and the
60-second quickstart
in the main README for the docker compose up + psql -f steps.
Quickstart
from amu_pgvector import AMUStore
from amu_pgvector.embeddings import fake_embedder
DSN = "postgresql://amu_owner:amu_owner_password@localhost:5433/amu_dev"
embed = fake_embedder(dim=1536) # swap for a real embedding model in production
admin = AMUStore(DSN)
admin.register_sensitive_column("income")
admin.grant_department_permission("Finance", "income")
admin.create_agent_role("finance_agent", "Finance", "finance_pw")
admin.create_agent_role("marketing_agent", "Marketing", "marketing_pw")
admin.record(
"SELECT avg(income) FROM customers",
{"avg": 82000},
metric_name="avg_income",
description="average customer income",
owner_department="Finance",
embed_fn=embed,
)
finance_dsn = "postgresql://finance_agent:finance_pw@localhost:5433/amu_dev"
marketing_dsn = "postgresql://marketing_agent:marketing_pw@localhost:5433/amu_dev"
AMUStore(finance_dsn).search("average customer income", k=5, embed_fn=embed)
# -> [SearchResult(metric_name='avg_income', ...)]
AMUStore(marketing_dsn).search("average customer income", k=5, embed_fn=embed)
# -> [] -- Marketing was never granted `income`, so Postgres itself
# never returns the row, regardless of how the query is asked.
What's in this package
AMUStore-- the client.record()extracts lineage from the SQL that actually produced a cached result (via amu-governance'ssql_lineage, not self-reported by an agent), computes itsdefinition_hash, checks for conflicting definitions, and inserts.search()runs entirely under the caller's own Postgres role, so row- level security gates it the same way it gates raw SQL. Admin helpers (register_sensitive_column,grant_department_permission,create_agent_role,register_materialization_edge) manage the governance policy.amu_pgvector.embeddings--fake_embedder()(deterministic, no network or model download) andsentence_transformer_embedder()(needs the[st]extra).amu-pgvector-mcp(the[mcp]extra) -- an MCP server exposingamu_search,amu_record, andamu_check_conflictas lineage-gated tools, listed on the MCP Registry asio.github.sangaraju1988/amu-pgvector.
For the LangChain integration (AMUVectorStore, AMURetriever), see
langchain-amu.
Links
- Main repo (SQL schema, quickstart, benchmarks, threat model): https://github.com/sangaraju1988/amu-pgvector
- Paper: Sangaraju & Vissa, IEEE Access, DOI 10.1109/ACCESS.2026.3730363
- Reference lineage library: amu-governance
- License: MIT
Release files for amu-pgvector 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| amu_pgvector-0.1.3.tar.gz | 19.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| amu_pgvector-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 30.2 kB
Release files / amu_pgvector-0.1.3.tar.gz
| Download URL | amu_pgvector-0.1.3.tar.gz |
|---|---|
| Size | 19.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5ee56cb13ee21ef444866ea1eccaeb5ea088ef4f029b54fa12e537f8712f14e0
|
|
BLAKE2b-256 checksum How to use checksums |
5a905b4e409f9705c223dbf2a3016a4e255054f1f150af138d9185801ad31b11
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency logRelease files / amu_pgvector-0.1.3-py3-none-any.whl
| Download URL | amu_pgvector-0.1.3-py3-none-any.whl |
|---|---|
| Size | 10.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1003b5e4d93057610b42f95b5b42b053265fd9ee36a9f9e27981713caebba756
|
|
BLAKE2b-256 checksum How to use checksums |
c72a912886b2e5eecfa86862c4c553923d5bbf2a46009d657a224092353c3011
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency log