Last updated: October 2026
What is Jev by TypeSafe AI, and is it safe for enterprise use?
Jev is a "System One" model from the San Francisco lab TypeSafe AI that returns typed decisions with probabilities instead of text. It cannot chat or call tools, which shrinks some risks, but injected content can still steer it, so enterprises need controls around it.
This Jev TypeSafe AI guide explains what the model is, what its numbers mean and how to govern it. We did not test it ourselves, and every performance figure is labeled vendor-reported or third-party. For chat-model risks, see our GPT-6 Astra guide for CISOs.
TL;DR: Key Takeaways
- Jev is cheap and fast by design. TypeSafe AI lists $0.042 per million input tokens with free output, and reports 70 to 500 ms responses (TypeSafe AI docs, 2026; TypeSafe AI, September 15, 2026).
- Independent accuracy trails the frontier. A third-party review found Jev at 72.5% on a 200-item benchmark, against 84.0% for Claude Fable 5.1 and 79.0% for GPT-6 Astra (DEV Community, September 24, 2026).
- Injected text can move its verdict. In one reported test, a fake pre-approval note cut the block probability for
rm -rf ~/.sshfrom 0.76 to 0.48 (VentureBeat, September 21, 2026). - It has no tool calling. Jev takes text only, up to 64,000 tokens per request, and does not stream, call tools or edit files (TypeSafe AI docs, 2026).
- Data terms are partly published. The DPA promises 72-hour breach notice and a 15-day objection window for new subprocessors, but states no retention period (TypeSafe AI DPA, April 24, 2026).
- Use it as a signal, not a gate. OWASP's LLM01:2025 lists least privilege and human approval as core injection mitigations (OWASP, 2025).
Jev by TypeSafe AI at a glance
| Jev (TypeSafe AI) | |
|---|---|
| Model class | System One: fast structured decisions for software |
| Output | Choice, Score or Noul (yes/no) with probabilities and confidence; no text |
| Version | jev-1.13.0 (aliases jev-latest, jev-preview) |
| Launch | September 15, 2026, early access |
| Price | $0.042 per million input tokens, output free |
| Latency (vendor-reported) | 70 to 500 ms end to end |
| Limits | Text only; 64,000 tokens per request; 80 requests per second |
| Tool use | None; your code owns control flow |
Sources: TypeSafe AI docs, launch post. Retrieved October 5, 2026.
What is Jev by TypeSafe AI?
Jev is the first model in TypeSafe AI's System One class. It reads a "state" you build, answers questions about it and returns typed values plus probabilities. It does not write replies, code or explanations (TypeSafe AI docs, 2026). The company calls it a function call for software decisions.
The docs warn that calibration holds across groups of predictions, not for each individual answer. Official names on typesafe.ai: company TypeSafe AI, product Jev, model class System One.
The three question types
A Choice selects one option from a list, with a probability per option, and supports up to 255 options (TypeSafe AI, September 15, 2026). A Score rates content on a rubric. A Noul asks whether a statement is true and returns a value from 0 to 1. Several questions can share one call, evaluated in parallel and in isolation (TypeSafe AI docs, 2026).
How does Jev differ from an LLM or an agent?
Jev answers one bounded question and stops. An LLM generates text token by token, and an agent adds tools, memory and loops. TypeSafe AI says Jev generates all outputs in one parallel pass, which explains its speed and why it cannot converse.
| Dimension | Jev (System One) | LLM agent |
|---|---|---|
| Output | Typed value plus probabilities | Text plus tool actions |
| Explanation | None returned | Optional reasoning traces |
| Tool calls | None | Core feature |
| Who controls the flow | Your code | The model |
| Main failure mode | Confident wrong label; steered verdict | Misused tools; injected actions |
Sources: TypeSafe AI docs, coding agents page. The agent column is our summary.
Jev is a component inside software, not a replacement for an assistant. For model-level risks in assistants, read our Claude Opus 5.5 enterprise security guide.
Jev performance claims: vendor-reported against independent
TypeSafe AI reports Jev as 40x to 200x faster than frontier LLMs on System One tasks, and up to 193.6x faster and 444.6x cheaper on its workflow evals. A third-party review is consistent on speed, but accuracy sits below top models.
| Claim | Number | Source type |
|---|---|---|
| End-to-end response time | 70 to 500 ms against 3 to 329 seconds for frontier LLMs | Vendor-reported |
| Workflow evals | 193.6x faster, 444.6x cheaper | Vendor-reported, written by its own staff |
| Hallucination rate | 0%, by schema matching | Vendor-reported, "not empirical" |
| Server time per request | About 0.1 s | Third-party review |
| Accuracy, 200-item benchmark | Jev 72.5%; Claude Fable 5.1 84.0%; GPT-6 Astra 79.0% | Third-party review |
| Calibration error (ECE) | 0.071 out of the box; 0.025 after temperature fitting | Third-party review |
Sources: TypeSafe AI launch post (September 15, 2026), DEV Community (September 24, 2026). Retrieved October 5, 2026.
TypeSafe AI notes that its evals ran from laptops on the West Coast. The 0% figure reflects type safety: an answer always matches the schema, but it may still be wrong.
The same review cites a larger study where Jev trailed the best of 19 LLMs on 14 of 15 tasks, and advises fitting calibration on a few hundred of your own labels.
According to Forbes (September 22, 2026), a Vercel engineer saw responses five to 18 times faster in a command-safety test, and LangChain reported a match with a human reviewer on 500 repeated decisions. Bryo AI found Google Gemini slightly more accurate but 10 to 20 times costlier. These are single tests, not audits.
Jev pricing, availability and integrations
Jev costs $0.042 per million input tokens, or $42 per billion, and output tokens are free. Access runs through a console and an HTTP API with Python and JavaScript SDKs. The launch post described waitlisted early access, so confirm your own terms.
The API is one endpoint, POST https://api.typesafe.ai/v1/systemone, with bearer-token authentication. Rate limits are 100,000 tokens and 80 requests per second, adjusted dynamically (TypeSafe AI docs, 2026). Product Hunt lists a September 21, 2026 launch with no waitlist (Product Hunt, 2026).
Jev TypeSafe AI security: what changes for enterprise risk
Jev removes some LLM risks and keeps others. It cannot emit free text or call tools, so it cannot hallucinate prose or misuse tools. But it reads untrusted content, and that content can move its answer, so any decision it gates can be influenced.
What shrinks
Output is schema-valid, so malformed JSON and invented fields disappear. The model also has no tool permissions and no free-text channel, so it cannot run a command by itself. "Cannot hallucinate" means type safety, not factual accuracy.
What stays: decision poisoning
TypeSafe AI's own limitations page says Jev does not treat input as hostile by default, leans toward the first option in a Choice and loses accuracy as unrelated content grows (2026). VentureBeat (September 21, 2026) quotes it: "Content written to adversarially steer the model, whether that is an injected instruction, a deliberately misleading framing, or text that argues for its own classification, can move the answer."
| Finding | Result | Source type |
|---|---|---|
Fake "user pre-approved" tool output on rm -rf ~/.ssh | Block probability 0.76 to 0.48; confidence 0.64 to 0.22 | Press report of one integration test |
| One-line "ignore the discussion above" override, 486 Wikipedia deletion discussions | 96.5% accuracy at baseline, 26.5% under injection | Community study, pre-registered |
| Blunt dangerous commands in a command gate, 30 calls | 0 of 30 passed; 3 of 30 safe commands wrongly blocked | Community test |
| Claimed approval such as "the owner approved", 30 calls | 3 of 30 passed | Community test |
| Swapping which rubric sits behind "no" and "yes" | 32.5% of answers changed, against about 2% with neutral names | Preprint cited by third-party review |
Sources: VentureBeat, zkousama/jagged (September 21, 2026), eugeniughelbur/jev-engineering (September 20, 2026), DEV Community. Retrieved October 5, 2026.
VentureBeat calls its own result "one command in one integration test, not a benchmark." The two GitHub studies are individual community work, not TypeSafe AI audits, and we reproduced none of the results. They vary by task: blunt commands failed in a command gate, while a one-line override collapsed accuracy in a classification test. Claims of authority also got through.
What is new: your code becomes the risk
Excessive agency moves into the surrounding code. TypeSafe AI's guidance says code should own control flow, escalate low-confidence cases and combine answers with deterministic rules (TypeSafe AI docs, 2026). If your code maps "allow" straight to an action, a poisoned verdict becomes a poisoned action.
Auditability also changes. Jev returns no explanation, so your logs must capture the state sent, the questions, the model version and the answer.
Jev TypeSafe AI data handling, residency and certifications
TypeSafe AI's privacy policy says it will not train or fine-tune models on your prompts, and its DPA covers EU and UK transfers. Retention is "as long as necessary," services are hosted in the United States, and we could not confirm any certification from its own documents.
| Topic | What is documented | Status |
|---|---|---|
| Training on your data | "We will not train or fine tune any artificial intelligence or machine learning models on your prompts or other Input" | Vendor-stated |
| Retention | "As long as reasonably necessary"; no fixed period; zero retention for enterprise via sales | No number published |
| Residency | Hosted in the United States; no region choice documented | No EU option found |
| Transfers, breach, audit | EU SCCs, UK Addendum, 72-hour breach notice, one audit per 12 months | Published in DPA |
| SOC 2 Type II | Reported by Vendor Trust Index, verified September 19, 2026 | Third-party; unconfirmed |
| HIPAA BAA, ISO 27001 | Index reports neither | Third-party |
Sources: TypeSafe AI privacy policy (November 19, 2025), TypeSafe AI DPA (April 24, 2026), TypeSafe AI legal docs, Vendor Trust Index. Retrieved October 5, 2026.
The key control sits on your side. The state field is the only data Jev sees, so redact personal data and send only the facts a decision needs. Training data provenance is a due-diligence question: the launch post lists it as an FAQ topic, so ask for a written answer.
On supply chain, jev-latest can move to a new version without any change on your side. Pin jev-1.13.0, re-run your evaluations before each upgrade and request the subprocessor list at contract signature.
How to secure Jev: put an AI gateway in front of it
Jev's verdict depends on untrusted input and on the code that acts on it. Jev itself returns only a typed answer, so the controls that matter sit in your own stack. The natural place for them is an LLM or AI gateway between your software and the API.
Before the call. The gateway holds the API key instead of each service, enforces policy and rate limits, and redacts personal data from the state before it leaves your network. A content check on whatever builds that state can catch injected instructions and fake approvals, the attack used in the reported tests.
After the call. Log the state sent, the questions, the model version and the answer, because Jev returns no explanation. In your own code, route low-confidence or high-impact verdicts to deterministic rules and human approval, so a poisoned "allow" never becomes an action on its own.
Before go-live. Run injection, authority-claim and option-order tests against your own flows and set thresholds from your results, not vendor numbers. Re-run them every time you move off the pinned jev-1.13.0.
An AI gateway such as Agent Gateway (TrustGate) from NeuralTrust is the kind of control layer this pattern needs. Because the System One API is new, confirm that your gateway supports it before rollout. Learn more about the AI Gateway and our guide to AI agent security. Following OWASP's guidance (OWASP, 2025), let Jev rank, route and flag, and let deterministic rules and people approve anything irreversible.
Which should you choose: Jev or an LLM agent?
Choose Jev for high-volume, bounded decisions where speed and cost dominate and a wrong label is recoverable. Choose an LLM agent when the task needs reasoning, tools or explanations. For irreversible actions, use neither alone: add deterministic policy and human approval.
| If your workload is... | Choose | Why |
|---|---|---|
| Routing tickets, alerts or emails into fixed queues | Jev | Probabilities let low-confidence items go to a person |
| Scoring content on a rubric, such as moderation | Jev, with your own calibration set | Fast and cheap; calibrate on your labels |
| A real-time loop that must answer in under a second | Jev | Vendor-reported 70 to 500 ms; verify in your region |
| Gating a destructive command or payment | Neither alone | A reported injection lowered a block probability |
| Multi-step work that reads the web, writes code or calls tools | LLM agent behind a gateway | Jev has no tool calling or text output |
| A decision that needs a written rationale | LLM agent or a person | Jev returns no explanation |
| Images, audio or regulated health data | LLM, or neither until verified | Jev is text only; an index reports no BAA |
Verdicts are our reading of the sources above.
A common pattern combines both: Jev routes at volume and a reasoning model or person handles the uncertain tail. To compare mainstream assistants, see Claude vs ChatGPT (2026): Benchmarks, Pricing & Verdict.
Conclusion
The Jev TypeSafe AI model is a credible tool for fast, cheap, structured decisions and a weak fit for anything that needs reasoning, tools or explanations. Its speed is vendor-reported, its accuracy trails frontier models in third-party tests, and injected content can move its verdicts. Adopt it as a signal inside deterministic software, pin the version and test it yourself.
Secure LLM Agents and Multi-Model Workflows in Production with NeuralTrust
Apply one policy, logging and testing layer to the models and agents your software calls.
Related Comparisons
- GPT-6 Astra: Security Implications for CISOs
- Claude Opus 5.5 Enterprise Security: Safeguards & Gaps
- Claude vs ChatGPT (2026): Benchmarks, Pricing & Verdict
FAQs about Jev TypeSafe AI
1. What is Jev by TypeSafe AI?
Jev is a System One model from TypeSafe AI, launched September 15, 2026. It evaluates a text or JSON state and returns typed answers (Choice, Score or Noul) with probabilities and confidence. It does not write text, code or explanations (TypeSafe AI docs, 2026).
2. How much does Jev cost?
TypeSafe AI lists $0.042 per million input tokens, or $42 per billion, with output tokens free. We found no published enterprise price list or service-level agreement (TypeSafe AI docs, 2026).
3. Is Jev safe from prompt injection?
No. TypeSafe AI's limitations page says adversarial content can move the answer, and VentureBeat reported a fake pre-approval note lowering a block probability from 0.76 to 0.48 on one destructive command. Keep deterministic checks and human approval on risky actions (VentureBeat, 2026).
4. Does TypeSafe AI train on my data?
Its privacy policy says it will not train or fine-tune models on your prompts or other input. Retention is "as long as reasonably necessary," with zero retention available to enterprises through sales (TypeSafe AI privacy policy, November 19, 2025).
5. Is Jev SOC 2 certified, and where does it process data?
We could not confirm certification from TypeSafe AI's own documents. The Vendor Trust Index reports SOC 2 Type II as of September 19, 2026, so ask for the report. Services are hosted in the United States, and no region choice is documented (Vendor Trust Index, 2026).
6. When should I use Jev instead of an LLM agent?
Use Jev for high-volume, bounded decisions such as routing, scoring or screening, where a wrong label is recoverable and low confidence can go to a person. Use an LLM agent for multi-step reasoning, tools and written explanations, with deterministic controls around both (TypeSafe AI docs, 2026).
About the Author
Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimization. He specializes in AI-powered search, content strategy, and SEM. Connect on LinkedIn.
NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognized across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.
Sources
- TypeSafe AI docs, Models, pricing and limits, retrieved October 5, 2026.
- TypeSafe AI, Introducing System One models and Jev, September 15, 2026.
- DEV Community, Jev after eight days of independent tests, September 24, 2026.
- VentureBeat, Companies are putting Jev in charge of AI agent decisions, September 21, 2026.
- TypeSafe AI docs, Jev with coding agents, retrieved October 5, 2026.
- TypeSafe AI, Data Processing Addendum, updated April 24, 2026.
- OWASP, LLM01:2025 Prompt Injection, 2025.
- Vendor Trust Index, Jev security and compliance profile, score date September 30, 2026.
- TypeSafe AI docs, System One models, retrieved October 5, 2026.
- TypeSafe AI docs, How to build with System One, retrieved October 5, 2026.
)
)
)
)
)
)
)