Research · US API · aliases

Vendor risk

Last updated: 2026-09-16

Legal and governance

What can a buyer inspect today?

Closed weights, no system card, no architecture paper, waitlist API, early access.[1][14] There is no public model card equivalent to a frontier-lab system card as of 16 September 2026. Governance of the use (what decisions the caller automates) sits entirely with the caller’s code and policy. TypeSafe’s “type-safe” claim does not transfer legal responsibility for a wrong Choice.

Cloud concentration

Where does the bytes-in / bytes-out path live?

Vendor says the service is currently based on the US West Coast; evals were run from laptops there.[1] No second region, no EU/Canada residency switch, no on-prem in the public docs. That is a single-cloud, single-vendor inference path.

Model continuity

What happens when jev-latest moves?

Docs tell you to send "jev-latest".[10] Version-looking aliases (jev-1.12, jev-1.13.0) have appeared in secondary write-ups; they were not the documented default on the API page reviewed here. Pinning, deprecation, and changelog policy are not public. A production caller who keys behavior to jev-latest probabilities is taking silent-update risk.

Data and control plane

What is “the document” the model sees?

State is the document. Whatever you put in state — ticket text, account JSON, traces — is the payload TypeSafe’s API receives.[32] Retention, training-use, and subprocessors are not on the public index. Until a DPA says otherwise, treat prompts as leaving your boundary.

Agent-runtime risk

If Jev is used as a gate, whose policy is it?

A Noul at 0.90 on “is this destructive?” is still your threshold, your false-negative cost, your agent’s tools.[28][9] Jev does not sandbox bash. A wrong low noul on a destructive command is an ordinary agent incident with a new judge in the path.

Lock-in

What would be expensive to unwind?

Question graphs, workflow evals written against TypeSafe primitives, and confidence thresholds tuned on Jev’s score distribution. The HTTP shape is unique; the idea (closed questions over state) is portable to a prefill replica or a future lab SKU.[18] Lock-in is in the eval suite and the thresholds, not in a proprietary SDK license.

FRFI / E-23 note

If a Canadian federal credit union put this on a live path, what would still have to be registered?

A US-hosted closed model used to score, route, or approve customer work is still an AI use under a model-risk program. The E-23-style registry row is the use (for example: “invoice hold / pay routing”), not the vendor’s claim that outputs are typed. Typed outputs do not create a Canadian inference region. This research is not advice to buy or not buy; it is the classification of the object.

← TaxonomyResearch references →