Where checked text goes
| Component | Destination |
|---|---|
| Transforms (regex, substrings, invisible text, Presidio, detect-secrets, canaries, token limits) | Your process |
| Judgments | TypeSafe, at https://api.typesafe.ai or your TYPESAFE_BASE_URL, after transforms |
| Judgments through OpenRouter | OpenRouter, which forwards them to Jev, after transforms |
Judgments on tev1 through Ollama | Your machine |
FakeBackend and other custom backends | Wherever that backend sends it |
Transforms always run before any judgment. The decision model sees the sanitized
projection: secrets redacted, input PII replaced by placeholders, retrieved
and tool-result PII masked, reply PII replaced by a per-check marker, and
invisible characters removed. On tool_call, secrets and pii block
without redacting, so the call itself keeps the arguments, but the judges see
them with the found values removed. Context values (prompt, question, sources, history) are
sanitized the same way. Placeholders are restored only in your process, in
check_output.
If no text may leave your machine, run tev1 on Ollama, run only
transforms, or put your own backend behind model= (see The judge).
Agent hooks
The hooks run the same way inside the uvx jes process the agent starts. They
also keep three things on disk, under ~/.config/jes/ (or $XDG_CONFIG_HOME/jes/):
| File | Contents | Mode |
|---|---|---|
.env | Your TypeSafe API key | 0600 |
config.json | Which guards run and their settings, no checked text | 0600 |
sessions/prompts/<session_id> | The last allowed prompt for that session, and nothing else | 0600 |
For Claude Code, the hook also buffers each streamed reply under
sessions/display/<session_id>/<message_id> until it is final, then deletes
it. Parts left unfinished are deleted after 24 hours.
Logging
- jes itself never logs checked text.
BackendErrormessages carry the backend name, the reason, and question ids, never request or response bodies. - The
langchain-typesafeclient owns HTTP. jes does not suppress its logs, or those of LangChain callbacks and tracing you enable. If you turn on LangChain tracing, for example to LangSmith, check whether it records classifier calls, which carry the sanitized text.