Jev in production › Agent guardrails and approvals
Enforces OS-kernel-level policy for AI coding agents and can call Jev as an optional pre-execution check alongside its syscall-level controls.
Runtime security for AI agents. Policy is enforced in the kernel, at the system call — below the agent, and below anything the agent writes. The agent's reasoning never gets a vote in whether an operation is allowed.
Jev is TypeSafe's System One model, which Ring Zero can call as an optional checks provider. Ring Zero is not affiliated with TypeSafe, and no TypeSafe code or model weights are bundled here — see NOTICE.
OpenAI's Agent security in the enterprise states the problem plainly:
For the project's own README, linking back here: