Jev in production › Agent guardrails and approvals

Ring Zero Security

Enforces OS-kernel-level policy for AI coding agents and can call Jev as an optional pre-execution check alongside its syscall-level controls.

Open on GitHub ↗

The source publishes no measured number.
Use
Agent guardrails and approvals
Industry
Security
Form
Open-source tool
Stage
Announced
Listed
2026-09-25
Found via
github
Repository
ringzerosec/jev-runtime-security
Stars
11
Forks
1
Last push
2026-10-11
Language
Rust
License
none stated

The README opens with

Runtime security for AI agents. Policy is enforced in the kernel, at the system call — below the agent, and below anything the agent writes. The agent's reasoning never gets a vote in whether an operation is allowed.

Jev is TypeSafe's System One model, which Ring Zero can call as an optional checks provider. Ring Zero is not affiliated with TypeSafe, and no TypeSafe code or model weights are bundled here — see NOTICE.

OpenAI's Agent security in the enterprise states the problem plainly:

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for agent guardrails and approvals