Questions for security reviewers
Security reviewers should assume hostile tickets and egress to a third party. This list is a start, not a pentest.
Independent. Jaggedness: adversarial content. docs.typesafe.ai.
Ask the implementers
- Where do keys live? Rotation?
- Which fields leave the VPC?
- Injection test set?
- Can a ticket rewrite instructions?
- Privileged auto-act on timeout?
- Log redaction?
- Door extra statuses handled (402, verification)?
- Who can lower floors?
Residual risk you will still own
Hosted model, adversarial state, gateway extra error codes, logs that contain ticket text, humans who rubber-stamp high confidence. Jev does not remove those. It adds a typed hop.
What this page does not claim
- Not an attestation.
FAQ
Is Jev a control? Only as a component inside your control.
Malware samples in state? Don’t. Extract indicators in a sandbox first.
Disclaimer
This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai. Never treat jev.pro as TypeSafe official documentation. We do not sell, issue, or proxy API keys.
Open-cluster pages are independent field-guide notes. Replicas and third-party interfaces mentioned anywhere on jev.pro are not Jev and not endorsed. Hub: Open. Siblings: security guide, questions for legal, vs security automation. Canonical: https://docs.typesafe.ai.
Sources
Public TypeSafe or adjacent documentation only. No private claims.