A security-operations experiment set that runs Jev as a first-line decision layer across SOC work: phishing classification, authentication triage, BEC detection, investigation routing, and prompt-injection detection, with a unified PhishGuard pipeline and an eval suite of staged states.
Each experiment defines typed questions over incident evidence — choices for incident type, ordered severity scores, and probabilities for escalation and credential theft — while deterministic policy and a System 2 handoff keep actions with humans and frontier models. The repository evaluates judgments rather than executing them; ambiguous or borderline signals route to deep analysis instead of automatic action.
How you can use it
To try this approach, gather real email examples, such as normal messages and suspicious payment requests. List the key details your team checks, like mismatched sender names or urgent links. You can test these samples directly in TypeSafe's web playground by pairing each email description with specific triage questions.
A developer can adapt the repository to evaluate incoming alert data for your team. Connecting your own systems to TypeSafe requires an API key, which is a software access code provided by the service. Because automated labels can make mistakes, set your rules so a human analyst reviews any borderline scores before taking action.