I know I’m a tad bit late with this post, but work took over and this post about the introduction to Jev stayed in drafts over two weeks. However, now, we are ready to go! TypeSafe AI released Jev on September 15, 2026. It’s the first of what they call “System One” models. You don’t chat with it, you just send it a state (text or JSON) and a set of typed questions, and it returns typed answers with probabilities. I spent some time with the docs and the Python SDK. This post covers what Jev is, whether it’s free, how to set up a client on Windows and Debian/Ubuntu, where it fits in security work, and the risks you should weigh before you point it at anything real.
What is Jev?
Jev is TypeSafe’s model – the first System One model that is built to make fast, structured decisions that softwares can use directly. It is a hosted as an API at https://api.typesafe.ai/v1/systemone and as of now, TypeSafe has not published weights or a self-hosting option.

Unlike some early media sources, the pricing for jev-1.13.0 is $0.042 per million input tokens as it not free. Output tokens cost nothing. That’s cheap, but it’s metered. However, until October 10, 23:59 UTC, n8n Cloud runs Jev on its own gateway credits, free!
How Jev thinks about a request?
There are three primary question types:
| Type | Asks | Returns |
|---|---|---|
Choice | Pick one option from a list | choice , probabilities , confidence |
Score | Rate against ordered levels | score , probabilities , confidence |
Noul | Is this statement true? | noul (0 to 1) |
You can mix all three in one call, and each question is evaluated independently against the same state, so adding questions barely adds latency.
My Jev Setup
You need Python 3.10 or newer and an API key from the Typesafe console. I pinned the SDK version below and at the time of writing that’s typesafe-sdk 0.7.2. Don’t go below 0.7.1 as that release stopped the SDK from including your API key in logged exceptions. On Debian/Ubuntu:
sudo apt update && sudo apt install -y python3 python3-venv
python3 --version # must be 3.10 or newer
mkdir -p ~/jev && cd ~/jev
python3 -m venv .venv
. .venv/bin/activate
pip install --upgrade pip
pip install "typesafe-sdk==0.7.2"
read -rs TYPESAFE_API_KEY && export TYPESAFE_API_KEY
On Windows, install Python 3.10+ from python.org or with winget install Python.Python.3.12 and then:
mkdir $HOME\jev; cd $HOME\jev
py -3 -m venv .venv
..venv\Scripts\Activate.ps1
python -m pip install --upgrade pip
pip install "typesafe-sdk==0.7.2"
$env:TYPESAFE_API_KEY = Read-Host -MaskInput "TypeSafe API key"
If Activate.ps1 is blocked, run Set-ExecutionPolicy -Scope Process RemoteSigned for that session only. Avoid setx for the key; it writes the secret into your user environment in the registry.
From the SDK constants:
| Variable | Default |
|---|---|
TYPESAFE_API_KEY | none |
TYPESAFE_BASE_URL | https://api.typesafe.ai |
TYPESAFE_DEFAULT_MODEL | jev-latest |
TYPESAFE_LOG_LEVEL | none |
The default request timeout is 10 seconds.
Let’s triage an advisory:
"""Minimal Jev check: triage one advisory paragraph. Needs TYPESAFE_API_KEY."""
import sys
from typesafe_sdk import Choice, Noul, Score, TypeSafeClient, TypeSafeError
ADVISORY = (
"A path traversal flaw in the web management interface lets a remote, "
"unauthenticated attacker read arbitrary files. The vendor reports "
"limited exploitation in the wild."
)
QUESTIONS = {
"weakness": Choice(
instructions="Which weakness class does this advisory describe?",
criteria={
"injection": "SQL, OS command, or code injection",
"path_traversal": "Reading or writing files outside the intended directory",
"auth_bypass": "Skipping or defeating authentication",
"memory_corruption": "Buffer overflow, use-after-free, or similar",
"other": "None of the above",
},
),
"remote_unauth": Noul(
instructions="Can an attacker exploit this remotely without credentials?"
),
"exploited": Noul(
instructions="Does the advisory say the flaw is exploited in the wild?"
),
"impact": Score(
instructions="How much data or system access does successful exploitation give?",
criteria=["Minor information leak", "Arbitrary file read", "Full system compromise"],
),
}
def main() -> int:
try:
with TypeSafeClient(model="jev-1.13.0") as client:
r = client.system_one(state={"advisory": ADVISORY}, questions=QUESTIONS)
except TypeSafeError as exc:
print(f"TypeSafe call failed: {exc}", file=sys.stderr)
return 1
w = r.choices["weakness"]
print(f"model={r.model}")
print(f"weakness={w.choice} confidence={w.confidence:.2f}")
print(f"remote_unauth={r.nouls['remote_unauth'].noul:.2f}")
print(f"exploited={r.nouls['exploited'].noul:.2f}")
print(f"impact={r.scores['impact'].score:.2f}")
return 0
if __name__ == "__main__":
sys.exit(main())
This is the first run response:
python3 triage.py
model=jev-1.13.0
weakness=path_traversal confidence=1.00
remote_unauth=0.96
exploited=0.75
impact=1.00
Where Jev fits in security?
TypeSafe’s own use-case map lists several security-adjacent jobs:
- LLM guardrails: Screen inputs, outputs, and tool calls for jailbreaks, prompt injection, policy violations, and sensitive-data exposure. There’s a full guardrails cookbook that routes each message to pass, review, block, or a support path.
- Financial crime and fraud: Score transaction narratives and alert histories, match entities across messy records, and route ambiguous cases to investigators.
- Semantic code linting: Encode team conventions as questions and run them in CI.
- Moderation and trust and safety: Combine severity and confidence to allow, warn, review, or block.
Some jobs I think fit the same shape, which TypeSafe doesn’t document now:
- Tagging vendor advisories with a weakness class and exploitation status before they hit a human queue.
- Routing SOC alerts by describing each alert’s fields as state and asking which playbook applies.
- Linting detection rules: does the rule’s description match what its logic actually matches.
I have seen examples of Jev being used as routing alerts, tagging ATT&CK techniques, ranking investigation candidates, first-pass scoring of telemetry, and guardrails on LLM agents. The point it makes that I agree with most: Jev can’t investigate. It only answers the questions you wrote.
What is Jev bad at?
TypeSafe publishes a list of known failure modes for jev-1.13 (Jev 1.13 jaggedness). The ones that bite security use cases:
- Numbers and dates: It doesn’t count reliably and doesn’t compare dates reliably. So, don’t ask it whether a CVSS score is above 7 or whether a patch date falls inside an SLA window. Do that in code instead.
- Low-level content: It does worse on assembly and binary-encoded instructions than on high-level languages. Read shellcode? Get another model.
- Literal reading: It answers the question you wrote, negations and all. Make sure to say exactly what you mean.
- Large, noisy state: Accuracy drops as irrelevant content grows. Filter logs before you send them. The hard limit is 64k tokens per request, with 32k for state plus the longest question (Models).
- No text generation: For extraction, find candidates with regex or a parser, then have Jev pick one.
Security risks of using Jev
- Prompt injection: TypeSafe says so directly that state is treated as data, not as hostile, and injected instructions or text that “argues for its own classification” can shift the result (Jev 1.13 jaggedness). If an attacker-controlled text reaches the state, assume it can steer the verdict. Keep deterministic checks in front and a human on consequential actions.
- “Can’t hallucinate” means “can’t return the wrong type.”: The launch post’s no-hallucination claim is about schema: you always get one of your defined options (launch post). The option can still be wrong. Pydantic’s docs point that Jev’s confidence “is a margin, not a probability that the answer is right,” and that reordering a Literal’s options “can move the answer.” Test with shuffled option order.
- Your data leaves your network. The privacy policy says TypeSafe won’t train on your input and won’t disclose it to third parties other than service providers. Retention is “as long as reasonably necessary.” Zero data retention is offered to enterprise customers only (Privacy Policy, Legal). On a self-serve key, don’t send customer data, credentials, or anything under NDA.
The Acceptable Use Policy limits security work. From the AUP (updated September 23, 2026):
- 1.5 bans uploading content, including input, that contains “viruses, malware, malicious code, or similar harmful materials.” No malware samples, no exploit PoCs, and think twice about raw phishing payloads.
- 3.7 bans probing, scanning, or testing TypeSafe’s own systems.
- 3.4 bans intentionally driving the model to act against TypeSafe’s policies. I don’t know how TypeSafe reads this for red-teaming your own Jev-based guard. Ask them in writing before you publish injection research.
Sites impersonating Jev are already out there! Search results for “Jev” include independent sites selling keys and “credits,” such as jev-ai.pro, which states it’s independently operated. These aren’t TypeSafe. Get keys only from console.typesafe.ai. Gateways like OpenRouter or Vercel apply their own billing and privacy terms, not TypeSafe’s (jev-agent.com). Be aware of sites such as jevmodel[.]org, jevtypesafeai[.]com. These clearly are attempts at phishing.
Benchmarks are vendor-run. The “193.6x faster, 444.6x cheaper” figures come from TypeSafe’s own workflow evals, which use GPT-6 Astra and Fable 5.1 as the reference answers. The launch post admits possible bias. Run it on your own labeled data before you trust it.
Supply chain and operations. The SDK depends on httpx2, which PyPI links to the pydantic/httpx2 GitHub repo. Pin versions, and use a lockfile with hashes for anything beyond a lab. Rate limits (100k tokens/s and 40 requests/s as I write this, down from 250k tokens/s at launch) can change without notice (Models), so any inline security control built on Jev needs a defined fail-open or fail-closed behavior when the API is slow or down.
My findings:
Jev is a cheap, fast classifier with calibrated-looking outputs and a clean API. For security, it fits jobs where a wrong answer costs a human a few seconds of review: triage, routing, enrichment. I wouldn’t put it alone in front of anything an attacker can write to.
It also isn’t alone anymore. In the two weeks since launch, Liquid AI, AWS, and Cloudflare have shipped decision models of their own, OpenAI has announced one in preview, and an open-source project serves Jev’s API on your own GPU. I plan to develop on this in the next few posts.
Leave a Reply
You must be logged in to post a comment.