NeuralTrust has been recognized by Gartner → Read more
Back

Jev TypeSafe AI: Enterprise Security Guide

Roger Howroyd October 6, 2026
Share
Jev TypeSafe AI: Enterprise Security Guide

Last updated: October 2026

What is Jev by TypeSafe AI, and is it safe for enterprise use?

Jev is a "System One" model from the San Francisco lab TypeSafe AI that returns typed decisions with probabilities instead of text. It cannot chat or call tools, which shrinks some risks, but injected content can still steer it, so enterprises need controls around it.

This Jev TypeSafe AI guide explains what the model is, what its numbers mean and how to govern it. We did not test it ourselves, and every performance figure is labeled vendor-reported or third-party. For chat-model risks, see our GPT-6 Astra guide for CISOs.

TL;DR: Key Takeaways

  • Jev is cheap and fast by design. TypeSafe AI lists $0.042 per million input tokens with free output, and reports 70 to 500 ms responses (TypeSafe AI docs, 2026; TypeSafe AI, September 15, 2026).
  • Independent accuracy trails the frontier. A third-party review found Jev at 72.5% on a 200-item benchmark, against 84.0% for Claude Fable 5.1 and 79.0% for GPT-6 Astra (DEV Community, September 24, 2026).
  • Injected text can move its verdict. In one reported test, a fake pre-approval note cut the block probability for rm -rf ~/.ssh from 0.76 to 0.48 (VentureBeat, September 21, 2026).
  • It has no tool calling. Jev takes text only, up to 64,000 tokens per request, and does not stream, call tools or edit files (TypeSafe AI docs, 2026).
  • Data terms are partly published. The DPA promises 72-hour breach notice and a 15-day objection window for new subprocessors, but states no retention period (TypeSafe AI DPA, April 24, 2026).
  • Use it as a signal, not a gate. OWASP's LLM01:2025 lists least privilege and human approval as core injection mitigations (OWASP, 2025).

Jev by TypeSafe AI at a glance

Jev (TypeSafe AI)
Model classSystem One: fast structured decisions for software
OutputChoice, Score or Noul (yes/no) with probabilities and confidence; no text
Versionjev-1.13.0 (aliases jev-latest, jev-preview)
LaunchSeptember 15, 2026, early access
Price$0.042 per million input tokens, output free
Latency (vendor-reported)70 to 500 ms end to end
LimitsText only; 64,000 tokens per request; 80 requests per second
Tool useNone; your code owns control flow

Sources: TypeSafe AI docs, launch post. Retrieved October 5, 2026.

What is Jev by TypeSafe AI?

Jev is the first model in TypeSafe AI's System One class. It reads a "state" you build, answers questions about it and returns typed values plus probabilities. It does not write replies, code or explanations (TypeSafe AI docs, 2026). The company calls it a function call for software decisions.

The docs warn that calibration holds across groups of predictions, not for each individual answer. Official names on typesafe.ai: company TypeSafe AI, product Jev, model class System One.

The three question types

A Choice selects one option from a list, with a probability per option, and supports up to 255 options (TypeSafe AI, September 15, 2026). A Score rates content on a rubric. A Noul asks whether a statement is true and returns a value from 0 to 1. Several questions can share one call, evaluated in parallel and in isolation (TypeSafe AI docs, 2026).

Try our AI Gateway today for free

How does Jev differ from an LLM or an agent?

Jev answers one bounded question and stops. An LLM generates text token by token, and an agent adds tools, memory and loops. TypeSafe AI says Jev generates all outputs in one parallel pass, which explains its speed and why it cannot converse.

DimensionJev (System One)LLM agent
OutputTyped value plus probabilitiesText plus tool actions
ExplanationNone returnedOptional reasoning traces
Tool callsNoneCore feature
Who controls the flowYour codeThe model
Main failure modeConfident wrong label; steered verdictMisused tools; injected actions

Sources: TypeSafe AI docs, coding agents page. The agent column is our summary.

Jev is a component inside software, not a replacement for an assistant. For model-level risks in assistants, read our Claude Opus 5.5 enterprise security guide.

Jev performance claims: vendor-reported against independent

TypeSafe AI reports Jev as 40x to 200x faster than frontier LLMs on System One tasks, and up to 193.6x faster and 444.6x cheaper on its workflow evals. A third-party review is consistent on speed, but accuracy sits below top models.

ClaimNumberSource type
End-to-end response time70 to 500 ms against 3 to 329 seconds for frontier LLMsVendor-reported
Workflow evals193.6x faster, 444.6x cheaperVendor-reported, written by its own staff
Hallucination rate0%, by schema matchingVendor-reported, "not empirical"
Server time per requestAbout 0.1 sThird-party review
Accuracy, 200-item benchmarkJev 72.5%; Claude Fable 5.1 84.0%; GPT-6 Astra 79.0%Third-party review
Calibration error (ECE)0.071 out of the box; 0.025 after temperature fittingThird-party review

Sources: TypeSafe AI launch post (September 15, 2026), DEV Community (September 24, 2026). Retrieved October 5, 2026.

TypeSafe AI notes that its evals ran from laptops on the West Coast. The 0% figure reflects type safety: an answer always matches the schema, but it may still be wrong.

The same review cites a larger study where Jev trailed the best of 19 LLMs on 14 of 15 tasks, and advises fitting calibration on a few hundred of your own labels.

According to Forbes (September 22, 2026), a Vercel engineer saw responses five to 18 times faster in a command-safety test, and LangChain reported a match with a human reviewer on 500 repeated decisions. Bryo AI found Google Gemini slightly more accurate but 10 to 20 times costlier. These are single tests, not audits.

Jev pricing, availability and integrations

Jev costs $0.042 per million input tokens, or $42 per billion, and output tokens are free. Access runs through a console and an HTTP API with Python and JavaScript SDKs. The launch post described waitlisted early access, so confirm your own terms.

The API is one endpoint, POST https://api.typesafe.ai/v1/systemone, with bearer-token authentication. Rate limits are 100,000 tokens and 80 requests per second, adjusted dynamically (TypeSafe AI docs, 2026). Product Hunt lists a September 21, 2026 launch with no waitlist (Product Hunt, 2026).

Jev TypeSafe AI security: what changes for enterprise risk

Jev removes some LLM risks and keeps others. It cannot emit free text or call tools, so it cannot hallucinate prose or misuse tools. But it reads untrusted content, and that content can move its answer, so any decision it gates can be influenced.

What shrinks

Output is schema-valid, so malformed JSON and invented fields disappear. The model also has no tool permissions and no free-text channel, so it cannot run a command by itself. "Cannot hallucinate" means type safety, not factual accuracy.

What stays: decision poisoning

TypeSafe AI's own limitations page says Jev does not treat input as hostile by default, leans toward the first option in a Choice and loses accuracy as unrelated content grows (2026). VentureBeat (September 21, 2026) quotes it: "Content written to adversarially steer the model, whether that is an injected instruction, a deliberately misleading framing, or text that argues for its own classification, can move the answer."

FindingResultSource type
Fake "user pre-approved" tool output on rm -rf ~/.sshBlock probability 0.76 to 0.48; confidence 0.64 to 0.22Press report of one integration test
One-line "ignore the discussion above" override, 486 Wikipedia deletion discussions96.5% accuracy at baseline, 26.5% under injectionCommunity study, pre-registered
Blunt dangerous commands in a command gate, 30 calls0 of 30 passed; 3 of 30 safe commands wrongly blockedCommunity test
Claimed approval such as "the owner approved", 30 calls3 of 30 passedCommunity test
Swapping which rubric sits behind "no" and "yes"32.5% of answers changed, against about 2% with neutral namesPreprint cited by third-party review

Sources: VentureBeat, zkousama/jagged (September 21, 2026), eugeniughelbur/jev-engineering (September 20, 2026), DEV Community. Retrieved October 5, 2026.

VentureBeat calls its own result "one command in one integration test, not a benchmark." The two GitHub studies are individual community work, not TypeSafe AI audits, and we reproduced none of the results. They vary by task: blunt commands failed in a command gate, while a one-line override collapsed accuracy in a classification test. Claims of authority also got through.

What is new: your code becomes the risk

Excessive agency moves into the surrounding code. TypeSafe AI's guidance says code should own control flow, escalate low-confidence cases and combine answers with deterministic rules (TypeSafe AI docs, 2026). If your code maps "allow" straight to an action, a poisoned verdict becomes a poisoned action.

Auditability also changes. Jev returns no explanation, so your logs must capture the state sent, the questions, the model version and the answer.

Jev TypeSafe AI data handling, residency and certifications

TypeSafe AI's privacy policy says it will not train or fine-tune models on your prompts, and its DPA covers EU and UK transfers. Retention is "as long as necessary," services are hosted in the United States, and we could not confirm any certification from its own documents.

TopicWhat is documentedStatus
Training on your data"We will not train or fine tune any artificial intelligence or machine learning models on your prompts or other Input"Vendor-stated
Retention"As long as reasonably necessary"; no fixed period; zero retention for enterprise via salesNo number published
ResidencyHosted in the United States; no region choice documentedNo EU option found
Transfers, breach, auditEU SCCs, UK Addendum, 72-hour breach notice, one audit per 12 monthsPublished in DPA
SOC 2 Type IIReported by Vendor Trust Index, verified September 19, 2026Third-party; unconfirmed
HIPAA BAA, ISO 27001Index reports neitherThird-party

Sources: TypeSafe AI privacy policy (November 19, 2025), TypeSafe AI DPA (April 24, 2026), TypeSafe AI legal docs, Vendor Trust Index. Retrieved October 5, 2026.

The key control sits on your side. The state field is the only data Jev sees, so redact personal data and send only the facts a decision needs. Training data provenance is a due-diligence question: the launch post lists it as an FAQ topic, so ask for a written answer.

On supply chain, jev-latest can move to a new version without any change on your side. Pin jev-1.13.0, re-run your evaluations before each upgrade and request the subprocessor list at contract signature.

How to secure Jev: put an AI gateway in front of it

Jev's verdict depends on untrusted input and on the code that acts on it. Jev itself returns only a typed answer, so the controls that matter sit in your own stack. The natural place for them is an LLM or AI gateway between your software and the API.

Before the call. The gateway holds the API key instead of each service, enforces policy and rate limits, and redacts personal data from the state before it leaves your network. A content check on whatever builds that state can catch injected instructions and fake approvals, the attack used in the reported tests.

After the call. Log the state sent, the questions, the model version and the answer, because Jev returns no explanation. In your own code, route low-confidence or high-impact verdicts to deterministic rules and human approval, so a poisoned "allow" never becomes an action on its own.

Before go-live. Run injection, authority-claim and option-order tests against your own flows and set thresholds from your results, not vendor numbers. Re-run them every time you move off the pinned jev-1.13.0.

An AI gateway such as Agent Gateway (TrustGate) from NeuralTrust is the kind of control layer this pattern needs. Because the System One API is new, confirm that your gateway supports it before rollout. Learn more about the AI Gateway and our guide to AI agent security. Following OWASP's guidance (OWASP, 2025), let Jev rank, route and flag, and let deterministic rules and people approve anything irreversible.

Which should you choose: Jev or an LLM agent?

Choose Jev for high-volume, bounded decisions where speed and cost dominate and a wrong label is recoverable. Choose an LLM agent when the task needs reasoning, tools or explanations. For irreversible actions, use neither alone: add deterministic policy and human approval.

If your workload is...ChooseWhy
Routing tickets, alerts or emails into fixed queuesJevProbabilities let low-confidence items go to a person
Scoring content on a rubric, such as moderationJev, with your own calibration setFast and cheap; calibrate on your labels
A real-time loop that must answer in under a secondJevVendor-reported 70 to 500 ms; verify in your region
Gating a destructive command or paymentNeither aloneA reported injection lowered a block probability
Multi-step work that reads the web, writes code or calls toolsLLM agent behind a gatewayJev has no tool calling or text output
A decision that needs a written rationaleLLM agent or a personJev returns no explanation
Images, audio or regulated health dataLLM, or neither until verifiedJev is text only; an index reports no BAA

Verdicts are our reading of the sources above.

A common pattern combines both: Jev routes at volume and a reasoning model or person handles the uncertain tail. To compare mainstream assistants, see Claude vs ChatGPT (2026): Benchmarks, Pricing & Verdict.

Conclusion

The Jev TypeSafe AI model is a credible tool for fast, cheap, structured decisions and a weak fit for anything that needs reasoning, tools or explanations. Its speed is vendor-reported, its accuracy trails frontier models in third-party tests, and injected content can move its verdicts. Adopt it as a signal inside deterministic software, pin the version and test it yourself.

Secure LLM Agents and Multi-Model Workflows in Production with NeuralTrust

Apply one policy, logging and testing layer to the models and agents your software calls.

Try our AI Gateway today for free

Related Comparisons

FAQs about Jev TypeSafe AI

1. What is Jev by TypeSafe AI?

Jev is a System One model from TypeSafe AI, launched September 15, 2026. It evaluates a text or JSON state and returns typed answers (Choice, Score or Noul) with probabilities and confidence. It does not write text, code or explanations (TypeSafe AI docs, 2026).

2. How much does Jev cost?

TypeSafe AI lists $0.042 per million input tokens, or $42 per billion, with output tokens free. We found no published enterprise price list or service-level agreement (TypeSafe AI docs, 2026).

3. Is Jev safe from prompt injection?

No. TypeSafe AI's limitations page says adversarial content can move the answer, and VentureBeat reported a fake pre-approval note lowering a block probability from 0.76 to 0.48 on one destructive command. Keep deterministic checks and human approval on risky actions (VentureBeat, 2026).

4. Does TypeSafe AI train on my data?

Its privacy policy says it will not train or fine-tune models on your prompts or other input. Retention is "as long as reasonably necessary," with zero retention available to enterprises through sales (TypeSafe AI privacy policy, November 19, 2025).

5. Is Jev SOC 2 certified, and where does it process data?

We could not confirm certification from TypeSafe AI's own documents. The Vendor Trust Index reports SOC 2 Type II as of September 19, 2026, so ask for the report. Services are hosted in the United States, and no region choice is documented (Vendor Trust Index, 2026).

6. When should I use Jev instead of an LLM agent?

Use Jev for high-volume, bounded decisions such as routing, scoring or screening, where a wrong label is recoverable and low confidence can go to a person. Use an LLM agent for multi-step reasoning, tools and written explanations, with deterministic controls around both (TypeSafe AI docs, 2026).

About the Author

Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimization. He specializes in AI-powered search, content strategy, and SEM. Connect on LinkedIn.

NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognized across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.

Sources

  1. TypeSafe AI docs, Models, pricing and limits, retrieved October 5, 2026.
  2. TypeSafe AI, Introducing System One models and Jev, September 15, 2026.
  3. DEV Community, Jev after eight days of independent tests, September 24, 2026.
  4. VentureBeat, Companies are putting Jev in charge of AI agent decisions, September 21, 2026.
  5. TypeSafe AI docs, Jev with coding agents, retrieved October 5, 2026.
  6. TypeSafe AI, Data Processing Addendum, updated April 24, 2026.
  7. OWASP, LLM01:2025 Prompt Injection, 2025.
  8. Vendor Trust Index, Jev security and compliance profile, score date September 30, 2026.
  9. TypeSafe AI docs, System One models, retrieved October 5, 2026.
  10. TypeSafe AI docs, How to build with System One, retrieved October 5, 2026.

Subscribe to our newsletter

Share

Join the leaders securing the agent ecosystem

Get a Demo