Jev (TypeSafe AI) on AWS: When System One Decisions Belong Next to Bedrock (2026)
Quick summary: Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s. On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model.
Key Takeaways
- Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s
- On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model
- On 15 September 2026, TypeSafe AI published Jev, the first System One model
- Input tokens are priced at $0.042 / MTok; output tokens are free
- Rechecked on 11 October 2026 against the TypeSafe models page: the pin is still , and the published rate limits are 100,000 tokens per second and 80 requests per second

Table of Contents
On 15 September 2026, TypeSafe AI published Jev, the first System One model. Unstructured state in; typed probabilistic decisions out. Input tokens are priced at $0.042 / MTok; output tokens are free. Rechecked on 11 October 2026 against the TypeSafe models page: the pin is still jev-1.13.0, and the published rate limits are 100,000 tokens per second and 80 requests per second. The earlier card of 250,000 tokens per second and 1,200 requests per minute is stale. TypeSafe says the current limits can still move without notice.
Jev is not an Amazon Bedrock model. The Bedrock model cards checked the same day do not list TypeSafe or Jev, and there is no Converse or InvokeModel model ID. On AWS it is a System-1 sidecar: your server calls TypeSafe for a closed-set decision; Amazon Bedrock stays the generator. Calling Jev from Lambda is a composition of two services, not evidence that AWS adopted Jev.
Opinionated take: use Jev for one bounded decision inside a flow you control. Use a Bedrock model when the user needs language or synthesis. Use deterministic code, IAM, and AgentCore Gateway policy before any side effect. Do not make Jev the controller of the agent, and do not treat a confidence score as authorization.
First-party signals we reuse (not a Jev outcome, not an agent client case) — Gateway server-side tools cut median tool round-trip ~180 ms → ~95 ms on a B2B CRM assistant (12 tools, ~8k turns/day) — Gateway post. Platform TCO silhouette: support-style AgentCore at 50K sessions/mo ~$791/mo platform + model (decision guide). Model your mix on the AgentCore pricing calculator. Jev sits next to that hop. It does not replace Gateway, Cedar, or Runtime.
Reproduce this — Clone the artifacts under
examples/architecture-blog-2026/jev-typesafe-aws/.python3 -m py_compile lambda_pydantic_ai_stub.pysyntax-checks the Python request shape. The TypeScript adapter isroute-support-ticket.ts(DRY_RUNdefaults on; no API key; no live Jev call). Ship gates live inmonday-checklist.md. Score the fit indecision-matrix.md. The CSV atcost-worksheet.csvworks TypeSafe’s published $0.042/MTok on one ticket-volume row.
Trade-off you accept: schema-bound decisions, with vendor-claimed tens-to-hundreds of milliseconds, in exchange for an egress dependency whose published cap (checked 11 Oct 2026) is 80 requests per second and 100,000 tokens per second, and which TypeSafe says can change without notice.
What Jev decides
TypeSafe named the class after Kahneman’s Thinking, Fast and Slow: System One for fast, structured judgments software can consume. Training is RLCD (Reinforcement Learning for Calibrated Decisions), not RLHF. Sampling is parallel across questions, not token-by-token.
That design gives up strings on purpose. Jev will not write a refund email, a Terraform module, or a toolUse JSON blob. A typed result picks among answers you listed. Your code maps that result onto a path you already allow.
TypeSafe’s marketing line is that Jev “can’t hallucinate.” Read that as cannot emit a value outside the schema. The Register, 16 Sep 2026, made the distinction we keep: a typed wrong answer is still wrong. A category can be spelled exactly right and still be the wrong category. Confidence exists so your code can refuse to act. It is not a probability that any single answer is correct. TypeSafe describes calibration across groups of predictions, not a guarantee on one ticket.
What Jev does not replace
Keep these jobs on other layers:
- Language and synthesis stay on a Bedrock foundation model: replies, summaries, explanations, and tool-argument text.
- Authorization stays on IAM, AgentCore Gateway policy, and your own checks. Gateway Cedar is default deny. A Jev score never satisfies it.
- Exact checks stay in code: a required disclosure sentence, an order-id format, a refund amount copied from the order record.
- Formal policy proof stays on Automated Reasoning Checks when you need valid or invalid against a policy, not a probability.
- Bedrock Guardrails stay on the generative call. They never see the TypeSafe hop. Production Guardrails guide.
Model card checked 11 Oct 2026
Source: TypeSafe Models. Re-read that page before you budget. TypeSafe says rate limits are adjusting dynamically.
| Field | jev-1.13.0 |
|---|---|
| Aliases | jev-latest and jev-preview both pointed here when we checked. No separate preview build. |
| Price | $0.042 / MTok input ($42 / billion tokens). Output tokens free. |
| Context | 64k tokens per request. 32k for state plus the longest question. |
| Input | Text only. String, JSON object, or array of text. No image, audio, or video. |
| Rate limits | 100,000 tokens/s and 80 requests/s. Over either limit: 429. SDK retries honor retry-after. |
| Fine-tune / LoRA | None. Shape answers with state, instructions, and criteria. |
| Training on your calls | TypeSafe says Jev is not trained on customer requests or responses. |
Pin jev-1.13.0 once a threshold is tuned. Aliases move when a release ships. The response model field reports the versioned ID that answered. Log that field.
Access paths, none of them Bedrock:
- HTTP:
POST https://api.typesafe.ai/v1/systemonewithAuthorization: Bearer - JavaScript / TypeScript:
@typesafe-ai/sdk—TypeSafeClient,client.systemOne(), helperschoice,noul,score - Python:
typesafe_sdk—TypeSafeClient.system_one(), classesChoice,Noul,Score - Default model if you omit
model:jev-latest(do not tune against it) - SDK default timeout: 10,000 ms per attempt, not a total budget across retries. Default
maxRetriesis 2 (three tries). Retried statuses include 408, 429, and 500–599. The HTTP API also documents529 Overloaded: back off, do not treat it as an answer.
English is the primary training language. Other languages, including CJK, are “handled but not equally well.” Test on your corpus before a non-English SLO.
Choice criteria cap at 255 options. Score levels cap at 10. Noul returns noul in 0–1 and no separate confidence. Choice and Score return confidence derived from the probability distribution. Do not copy a Noul threshold onto a Choice.
Jev is not a Bedrock model
Checked 11 Oct 2026:
- Bedrock’s published provider list (Amazon, Anthropic, Meta, Mistral, OpenAI, and the rest of the model cards) does not include TypeSafe.
- There is no Jev model ID on
bedrock-runtimeforConverseorInvokeModel. - TypeSafe documents one endpoint,
api.typesafe.ai. We found no Bedrock-native adapter, inference profile, or PrivateLink. - Agent Toolkit for AWS guides coding agents with skills and authenticated AWS tooling. It does not host Jev and it is not a model-catalog listing.
A Lambda function that calls TypeSafe is your integration. It does not put Jev inside the Bedrock data perimeter, and Bedrock Guardrails do not wrap it.
Recommended architecture
Use Jev for bounded, typed decisions. Use Bedrock foundation models for language and complex reasoning. Use deterministic application logic and explicit policies to control side effects.
The default pattern is an application-owned pre-router. One server-side systemOne call. An allowlist in your code. Bedrock only on routes that need a draft. Jev is not invoked on every agent step, and it does not choose shell commands, URLs, SQL, or raw tool arguments.

Figure 1. Production path. Jev stays outside the AWS account. The adapter owns the route. Gateway policy still has to allow any tool call.
| Layer | What runs | What it must not do |
|---|---|---|
| Entry | API Gateway, Lambda, or AgentCore Runtime | Send the raw request to Jev before auth and schema checks |
| Decision | Server adapter, POST /v1/systemone, model jev-1.13.0 | Return a tool name, URL, or SQL string for direct execution |
| Route | Your threshold and an allowlist | Treat low confidence, timeout, or 429 as a category |
| Language | Bedrock Converse plus Guardrails | Ask Jev to write the reply because the decision was typed |
| Side effects | IAM, Gateway Cedar, a deterministic argument check, human approval where the impact is high | Use Jev confidence as the only allow |
| Network | NAT or other explicit egress to api.typesafe.ai on 443 | Assume a Bedrock VPC endpoint covers TypeSafe |
| Secret | Secrets Manager (or the platform secret store) → TYPESAFE_API_KEY | Put the key in a browser bundle or a CloudWatch message |
| Observe | CloudWatch: model id, outcome, latency, 429 count, input tokens | Log the ticket body or the API key |
For a VPC workload, the subnet needs a path out: NAT Gateway, or another egress design you already operate, plus a security group that allows TCP 443 to the TypeSafe API. Flow logs will show that destination. We did not find a TypeSafe PrivateLink or a Bedrock VPC endpoint that proxies Jev.
Where the decision sits in orchestration
Pick one insertion point. Do not stack all of them on every turn.
| Pattern | Use it when | Cost of the extra hop |
|---|---|---|
| Pre-router (default) | The next step is one of a few workflows you can name in advance | One TypeSafe call before any Bedrock tokens |
| Strands custom tool | An agent is already running and needs a bounded classification mid-turn | Only that step. Not every tool call. |
| Existing Bedrock Agent action group | You already have an action group and a Lambda. Do not start a new Agents Classic build for this. | Same external call, inside the older tool loop |
| Post-draft screen | You want a bounded property of a generated reply | Jev sees the draft, so the draft must be allowed to leave AWS |
| Async classifier | Catalog or document volume where a sync hop would sit on the user path | SQS or EventBridge. Failures go to a DLQ, not to a default “approved” |
Strands has no Jev provider. A custom tool should call the same adapter and return a route name your code already understands. The model that is driving the agent must not be free to invent a Gateway tool from a Jev string. If the product is a Strands agent on AgentCore Harness or Runtime, keep Jev beside that loop, not inside every iteration. LangGraph can host the same classify node. Jev is not the graph.
AgentCore Gateway’s MCP targets, Cedar policies, and Lambda request/response interceptors authorize and shape tool calls. They do not classify the user message, and they do not see TypeSafe. A request interceptor can enrich context before Cedar runs; that is still your code and your policy, not a Jev confidence check. Multi-account Gateway access is an account-boundary problem. It is not a reason to pretend the TypeSafe call stayed inside AWS.
Agent Toolkit skills help a coding agent follow AWS practice while you build this. They are not the production decision path.
TypeScript adapter
Context: Node.js 20+, @typesafe-ai/sdk, model jev-1.13.0. The module below is the companion file. DRY_RUN defaults to on, so importing it does not call TypeSafe. DRY_RUN=0 is the live path and still does not refund anyone.
The application lists the only categories Jev may return. refund_candidate opens review. It does not call a payments API. A timeout, a 429, and a low-confidence Choice are different outcomes. Noul uses its own threshold.
// examples/architecture-blog-2026/jev-typesafe-aws/route-support-ticket.ts
// DRY_RUN defaults on. No browser key. No refund call.
const MODEL_ID = "jev-1.13.0";
const CHOICE_CONFIDENCE_MIN = 0.8; // placeholder — calibrate on your set
const REFUND_NOUL_REVIEW_MIN = 0.85; // Noul probability, not Choice confidence
const SUPPORT_CATEGORIES = {
order_status: "Tracking, delivery, or a missing parcel.",
refund_candidate:
"Duplicate charge or an explicit refund request. Opens review. Does not issue a refund.",
product_question: "Fit, quality, or how to use an item.",
other: "None of the above.",
} as const;
function applyPolicy(answers: {
model: string;
category: string;
confidence: number;
noul: number;
}) {
if (answers.category === "refund_candidate") {
if (answers.confidence < CHOICE_CONFIDENCE_MIN) {
return { outcome: "human_review" as const, reason: "low_confidence" as const };
}
return { outcome: "review_refund" as const }; // review workflow, not a refund
}
if (answers.noul >= REFUND_NOUL_REVIEW_MIN) {
return { outcome: "human_review" as const, reason: "refund_signal_disagreement" as const };
}
if (answers.category === "other" || answers.confidence < CHOICE_CONFIDENCE_MIN) {
return { outcome: "human_review" as const, reason: "low_confidence" as const };
}
if (answers.category === "order_status" || answers.category === "product_question") {
return { outcome: "draft_with_bedrock" as const, category: answers.category };
}
return { outcome: "human_review" as const, reason: "low_confidence" as const };
}
async function askJev(state: { ticket_message: string; refund_policy: string }) {
const client = new TypeSafeClient({
timeout: 8_000, // SDK default is 10_000 ms per attempt
retry: { maxRetries: 1 }, // SDK default is 2
});
const result = await client.systemOne({
model: MODEL_ID,
state,
questions: {
category: choice("Which support category owns `ticket_message`?", SUPPORT_CATEGORIES),
refund_requested: noul("Does `ticket_message` request a refund?"),
},
});
return {
model: result.model,
category: result.answers.category.choice,
confidence: result.answers.category.confidence,
noul: result.answers.refund_requested.noul,
inputTokens: result.usage.input_tokens,
};
}The full module catches APITimeoutError, RateLimitError, BadRequestError, and APIConnectionError, logs model, outcome, latency, input-token count, and requestId when the error is an APIError, and returns outcome: "unavailable". It does not log state or TYPESAFE_API_KEY. The SDK reads the key from the environment, refuses browser use unless you set dangerouslyAllowBrowser (do not), and defaults baseURL to https://api.typesafe.ai.
On the live path, load the key from Secrets Manager into the task environment. The caller that receives draft_with_bedrock may then call Bedrock. The caller that receives review_refund opens a human or policy workflow. Neither branch is implemented in the sample, on purpose.
A Strands tool, if you need one mid-turn, should call routeSupportTicket and return the outcome name. Shape only — this snippet is not the typechecked sample, and Strands will still try to call the tool when its model decides to:
const classifyTicket = tool({
name: "classify_support_ticket",
description: "Return an application route name. Does not refund or mutate orders.",
inputSchema: z.object({
ticketMessage: z.string(),
refundPolicy: z.string(),
}),
callback: async (input) => {
const route = await routeSupportTicket(input);
return route.outcome;
},
});Prefer the pre-router so the agent model never chooses whether classification runs. The Python stub in the same folder (typesafe_sdk, system_one, DRY_RUN=1) is the same policy in the other SDK. Pydantic AI’s TypeSafeModel can map an output_type onto Jev questions; a Bedrock model behind FallbackModel still has to write tool arguments. Gateway policy still allows or denies the write.
E-commerce decision boundaries
These are designs, not FactualMinds customer results. There are no published agent engagements to cite here.
Support routing. Jev Choice over order_status, refund_candidate, product_question, and other, plus a Noul for refund intent. Application code opens the queue. A Bedrock model drafts a reply only after the route is draft_with_bedrock. A refund candidate enters review even when confidence is high.
Retrieval strategy. A second Choice can pick catalog, policy_docs, order_api, or human, but only if those strings are keys in a map you wrote. The map’s values are the Gateway tool names or internal handlers you already registered. If Jev returns something absent from the map, you escalate. Jev does not get to mint a tool.
Output screening. After Bedrock drafts a reply, deterministic checks come first: the order id matches the account, a required returns sentence is present, the refund amount was not invented. Use Jev only for a fuzzy property you cannot grep, such as “this draft promises a remedy the policy does not allow,” and only after you have labeled enough drafts to know the false-negative rate. A schema-valid “ok” is still not proof the draft is safe to send.
Async classification. Catalog copy, old tickets, or ingested documents belong on SQS or EventBridge, with a concurrency cap under the 80 requests/s published limit and a DLQ. Do not add a synchronous TypeSafe round trip to a product-page render to score a document you could have classified when it was written.

Figure 2. One request. Validation, one Jev call, then your policy. Errors and low confidence leave the happy path.
Security, privacy, and policy
Sending state to TypeSafe crosses a network and a processor boundary outside the AWS account. TypeSafe’s legal page points at a DPA, a privacy policy, and zero data retention for enterprise customers via sales. That is a contract you have to sign and configure. It is not a property of the default API, and it is not an AWS BAA. Do not promise residency because the rest of the stack is in us-east-1.
Minimum payload: the ticket text and the policy sentence the question needs. Not the full customer profile, not a PAN, not a clinical note.
Side effects stay on independent controls:
- The adapter maps a category to an allowlisted operation.
- IAM scopes what the task role can call in AWS.
- AgentCore Gateway Cedar permits or forbids the tool. Forbid wins. No matching permit means deny.
- A Lambda interceptor can enrich or strip a tool request. It should not “ask Jev again” as a substitute for Cedar.
- Deterministic validation checks amounts, ids, and ownership against your database.
- A person approves refunds, PII export, account changes, inventory mutations, and production deploys.

Figure 3. Jev suggests a label. The allowlist, IAM, Gateway policy, and a deterministic check each still have to pass. None of them reads Jev confidence as an allow.
What broke — Paper architecture, week of 15 Sep 2026 launch notes: put raw HIPAA support mail in Jev
stateto classify “refund vs medical question” before an AgentCore Gateway write. That design fails three independent controls at once. (1) The payload egresses toapi.typesafe.ai; Bedrock Guardrails never see it. (2) Cedar on Gateway cannot authorize TypeSafe. (3) TypeSafe’s DPA / ZDR is an enterprise paperwork path, not an AWS BAA. Detection: NAT Gateway / VPC flow logs to TypeSafe. Rollback: classify with a Bedrock model in-region under the existing BAA, or strip to non-PHI features (queue enum, order-id only) before any third-party call. We did not run this against a client mailbox. We are refusing the design on controls, not on a measured latency.
Customer-origin text is hostile until you prove otherwise. TypeSafe does not treat state as an untrusted instruction channel by default. The same injection rule you use on Bedrock applies to the text you forward.
Evaluation, confidence, and fallback
Decide whether Jev earns the egress with a labeled set: anonymized tickets or synthetic tickets you wrote, with the category and the refund bit marked by a person. Compare at least:
| Approach | What you learn |
|---|---|
| Rules, then Bedrock for the draft | Whether the branch was already in the order system |
| Bedrock-only routing | Accuracy and cost when one model both labels and writes |
| Bedrock with constrained output | Whether schema-bound generation is enough without a second vendor |
| Jev plus the allowlist in this post | Accuracy, calibration, and the review rate on the same labels |
| Hybrid | What fraction of tickets hit Jev, what fraction fall back, and the cost of both |
Measure decision accuracy, confidence calibration, false positives and false negatives on refund_candidate, the share sent to review, end-to-end p50 / p95 / p99, API errors, 429s, timeouts, retries, and cost per successful task (Jev input, retries, NAT, Bedrock, and human review). Also count how many Bedrock calls and tool calls the router avoided or added. Do not promote Jev because a vendor multiplier looked large.
TypeSafe’s launch post claims 70–500 ms end-to-end and, on their workflow evals, 193.6× faster / 444.6× cheaper than frontier LLMs wrapped in the same decision API. They also wrote the caveat: those multipliers sit on the higher end, and the latency traces were generally run from West Coast laptops against a West Coast service. That is not the latency from your AWS region through NAT. We have not called the API, so this post has no first-party p50.
There is no universal confidence cutoff. 0.8 in the sample is a placeholder so the code has a branch. Fit the cutoff on your distribution. A low-confidence support category can fall through to a Bedrock classifier, a rules path, a clarification question, or a person. A timeout, 429, or 529 must not fall through as if Jev had picked order_status.
For a user-facing route, bound retries (the sample uses one retry and an 8 second attempt timeout, inside the SDK defaults of two retries and 10 seconds). Open the circuit if 429s cluster, and serve the in-account fallback. High-impact operations fail closed when the check does not finish: no refund, no export, no inventory write.

Figure 4. Failures are visible outcomes. None of them is an implicit allow.
Cost and latency
One synthetic row, not a second invented workload. Assume 1,000,000 support tickets and 500 input tokens each (message, a short policy snippet, and the question text), questions batched so the ticket is sent once. That is 500 MTok.
500 × $0.042 / MTok = $21 of Jev input. Output tokens are $0 on TypeSafe’s card.
That $21 excludes Lambda or Runtime, NAT bytes, retries, CloudWatch, the Bedrock draft, and review time. A 429 retry pays the input again if TypeSafe metered the attempt; confirm that on your invoice rather than assuming it away. Thirteen serial calls would re-pay a large state. TypeSafe’s parallel-questions cookbook, on jev-1.12, batched 13 questions over a ~54k-character article and reported 12.2× cheaper / 10.0× faster than 13 serial calls ($0.000497 vs $0.006090; 0.27 s vs 2.71 s). That is a document-dominated vendor example. A 500-token ticket will not print a 12×.
| Path | Use it when | What you pay besides “the model” | Trade-off |
|---|---|---|---|
| Bedrock only | One model should both label and write | Output tokens, Guardrails, tool calls | No TypeSafe egress. You still have to parse the label. |
| Rules, then Bedrock | The branch is already in DynamoDB or the event | Bedrock only for the draft | Do not pay $0.042/MTok for an if |
| Jev, then Bedrock | The label is closed-set and the payload may leave AWS | Jev input, NAT, then Bedrock if a draft is required | Extra network hop. Best as a pre-router, not every step. |
| Jev alone | You need a label and no customer-facing prose | Jev input, NAT, retries | No reply text. Still not authorization. |
| Hybrid with fallback | Low confidence or a TypeSafe error must stay safe | Whichever path ran, plus review | A timeout is not a cheap success. |
Platform context you already have: support-style AgentCore at 50K sessions/mo ~$791/mo. Jev’s $21 at a million tickets is a model-API line, not a replacement for that silhouette. AgentCore’s own controls for behavior and spend sit on the agent session; they do not meter api.typesafe.ai. For a Bedrock classifier on the same labels, use the Bedrock pricing page and the token-budget post. The worksheet leaves those cells as formulas so this page does not invent a second rate card.
Budget latency as a sum you measure: TypeSafe’s claimed 70–500 ms, plus your NAT and TLS, plus Bedrock only on routes that draft. Add the Gateway canary (~95 ms median tool RTT in the CRM assistant) only on turns that actually call a tool. Do not subtract Jev from that canary. We have not timed Jev in that account.
Named substitutes
| If you need… | Use this | When |
|---|---|---|
| In-account classification | Amazon Nova Micro (or another small Bedrock model) on Converse | PHI, residency, or IAM must stay in the account. Price from the Bedrock pricing page. |
| Denied topics, PII filters, grounding | Bedrock Guardrails | The generative call is already on Bedrock. |
| “Is this answer allowed by policy?” | Automated Reasoning Checks | Formal logic, not a probability. |
| Deterministic branches | Step Functions plus DynamoDB or EventBridge | The set is in your database. |
| An explicit agent graph | LangGraph on AgentCore Runtime | Jev can be a classify node. It is not the graph. |
| A single-domain agent loop | Strands on AgentCore | Add a custom tool only for a bounded question. Do not add a third-party model to skip configuration. |
| Extract-then-pick | A parser, then a Jev Choice or Bedrock structured output | Do not ask Jev to generate the value. |
We recommend the pre-router in front of Bedrock, not Jev instead of Bedrock, when the decision is closed-set, legal has accepted the egress, and you will operate confidence and 429 metrics for a shadow week. We recommend Nova Micro or rules when the payload cannot leave, or when you have not yet run that week.
What to Do This Week
- Residency first. If
statecan contain PHI, PCI, or a named-region clause, stop. Stay on Bedrock. - Pin
jev-1.13.0. Re-read the models page the day you deploy. The 11 Oct 2026 limits were 80 requests/s and 100,000 tokens/s. - Write atomic questions against one anonymized ticket. No “decide the action.” Include
otheron every Choice. - Put the key in Secrets Manager. Confirm the client is not constructed in a browser bundle.
- Log outcome,
model, latency, and token count to CloudWatch. Do not log the ticket. - Shadow against a Bedrock classifier or your rules before any customer traffic. Promote only on disagreements you can explain.
- Keep Cedar and a deterministic check on the write. Run
monday-checklist.mdand fillcost-worksheet.csvwith your token counts.
If you only do one thing: do not send customer text to TypeSafe until legal has a sentence about egress.
What This Post Doesn’t Cover
- We have not called the Jev API. No first-party p50/p95, no error rate, no
429trace. The 70–500 ms band and the 193.6× / 444.6× multipliers remain vendor claims. - The TypeScript module typechecks against
@typesafe-ai/sdk@0.6.0(11 Oct 2026) in a side directory. It does not perform a live call. The Strandstool()sketch was checked against Strands’ custom-tool docs and was not executed. - Jev was not in the Bedrock model catalog or Marketplace listing we could see on 11 Oct 2026. A future listing would change the IAM and network story. This page would be wrong until it is revised.
- No documented PrivateLink or Bedrock VPC endpoint for TypeSafe. If AWS or TypeSafe publishes one, the egress section changes.
- Enterprise ZDR, DPA terms, and any BAA-equivalent. Read the contract. Do not infer it from this post.
- A production Strands or AgentCore deploy of the adapter. The sample returns a route object.
- Any FactualMinds AI-agent case study. Permitted proof here is the field guide, the calculators, the Gateway canary, and cited vendor numbers.
Editable diagram sources: examples/architecture-blog-2026/jev-typesafe-aws/diagrams/.
Frequently asked questions
What is Jev from TypeSafe AI?
Is Jev available on Amazon Bedrock?
When is Jev a good fit next to Amazon Bedrock?
When should we NOT use Jev on AWS?
What could go wrong if we send production tickets to Jev?
Does a typed Jev answer mean the decision is correct?
Can Jev replace Bedrock Guardrails or Automated Reasoning Checks?
Where should Jev sit in a Strands or AgentCore agent?

AWS Cloud Architect & AI Expert
AWS-certified cloud architect and AI expert with deep expertise in cloud migrations, cost optimization, and generative AI on AWS.




