← Back

Release

Everyone is pointing this model at their content. We pointed it at policy.

System One models classify content by answering typed questions, in under half a second, for four cents a million tokens. A fortnight after Jev shipped they are everywhere. Squidder now supports them, as the judge behind your policies and as traffic your applications can send.

Manah Khalil/

TypeSafe released Jev on 15 September and opened it to everyone on the 20th. It does one thing. You hand it a piece of content and a set of typed questions, and it answers them with probabilities: a yes or no as a number, one option from a list, a score on a scale you describe in words. It never writes prose, which is the point.

It is a classifier, and the internet spent a fortnight working out that it is a very good one. Around thirty open reproductions have shipped since launch, every gateway worth the name has added a route to it, and people are pointing it at support tickets, listings, documents and moderation queues.

We support it too. But the interesting place to point a classifier, if you already run a gateway, is not at the content going past. It is at the policy deciding what happens to that content, because a policy is exactly a list of typed questions asked of a piece of content.

The figures are what make it a different kind of component rather than a better chat model. On TypeSafe's published numbers: an answer in 70 to 500 milliseconds where a frontier model takes seconds, a structured output error rate of zero because it never writes text at all, and input priced at $0.042 per million tokens with output free.

Two of those matter more than they look. It returns a value from a set you defined, so it cannot invent a category that does not exist or phrase a verdict your gateway is unable to read. And it is trained for calibration, so the probability is the thing it was built to get right. A chat model's confidence score is a number it made up about itself, which is why a threshold on one never quite means anything.

What it changes

Inspection is inline, so whatever judges your policies sets the pace and the price of governing. That has always been the number worth watching, and this month it moved.

A judge that answers in under half a second, cannot fail to return something readable, and charges four cents a million tokens to read your traffic makes inspecting a request cost close to nothing, in time and in money. Turn the policies on across every surface and every application you have, and the arithmetic still works.

That compounds with how the gateway asks. Every rule that applies to a request is asked together, in one call, so a policy carrying twenty checks is one round trip rather than twenty. Price and latency are per call, which is where the two meet: governing a request thoroughly costs about what governing it lightly does.

There is a second-order effect worth more than the first. "Does this look like an attack" is unbounded judgment over arbitrary text, and it takes a frontier model to get close while still firing on ordinary content. "Does this match the thing I described" is a bounded comparison against a reference you supplied. You do not buy accuracy with a bigger model. You buy it by giving a better question to a smaller one, and there is now a model built for the question.

Within days, gateways added Jev to their model lists. That is a route: your application can reach the model through them, priced and recorded like any other call. Useful, and table stakes. We did something else with it, in two places.

One: a judge worth choosing

Squidder has always let you name the model that judges your policies, and you choose it the way you choose any model: on cost, accuracy and latency. It is a real decision, made deliberately, and different policies deserve different answers to it.

Until this month, every option on that triangle was a chat model, so where you landed on it came down to which chat model you picked. A System One model is a different point on the triangle altogether, and it is built for exactly the question a policy asks.

What is new is what now sits beside them on the list. You add a System One model the way you add any other: pick the provider, give it a key, put it on an allowlist.

That can be TypeSafe's hosted Jev, if you would rather somebody else ran it. It can equally be one of the open models, which arrived faster than anyone expected: around thirty reproductions have shipped since Jev launched, and the ones worth knowing about, Laya, Kev and Von among them, publish their weights under permissive licenses and answer the same interface. Point the gateway at one of those on hardware you own and nothing about your traffic leaves the building. We support the interface rather than a vendor, so the choice stays yours when something better appears next month.

You name it on the policy rather than on each rule, so one model answers every check that policy holds. It is called the judging model, and it is not inherited from anywhere: a policy is the only place it is set.

That covers three kinds of policy. On a content policy the judge decides whether written content matches what you described. On a routing policy it decides which model answers a prompt, without answering the prompt itself. On a tagging policy it decides what the record is labelled with.

And you can run it yourself before you trust it. Give the model a piece of content and the questions you mean to ask of it, and it answers them in front of you, with the probability on each and whether it crosses your threshold. If you are going to let a model decide whether to block your traffic, you should be able to watch it work first.

Two: the judge is traffic, and it is governed

Your applications are going to start calling these directly, and the same figures are the reason. At sub-second answers and four cents a million, a typed decision becomes affordable inside a loop: route this ticket, is this listing acceptable, which of nine things is the customer asking for. Work that was too slow or too expensive to ask a model about, per item, at volume, is now neither.

So the traffic arrives whether or not anybody planned for it, carrying your content to somebody else's model, from code written in an afternoon because the call is cheap to make.

In Squidder, System One is a surface of its own, alongside LLM, web and the agent protocols, with its own access switch. An application calling one meets what any other call meets: the model allowlist, the limits, and a row in your request log with its usage and its cost.

One detail for whoever owns the bill. The application owner pays for the judge's call, the same as for the traffic that triggered it, and it lands on their bill as inspection cost rather than disappearing into what they spent answering their users. Governing becomes a line with an owner instead of overhead nobody can see, and the team deciding how much to inspect is the team that can read what inspecting costs them.

Getting started

Add TypeSafe as a provider with your key, or point Squidder at your own server speaking the same interface. Put the model on an allowlist, open the policy that holds the checks you care about, and name it as the judging model.

Content policies start switched off on System One, so turn them on for the app, group or tenant whose traffic you want read. If the judge is a vendor's model rather than one you run, turn on the setting that permits a third-party judge.

One caution on the key: TypeSafe paused new signups on 22 September after demand. The open models speak the same interface and run on hardware you own, which is the version where your content does not leave the building anyway.