Bank vendor-risk review and DPA for Jarvis.

What does the security review cover?

Banks can request a DPA for Jarvis (getjarvis.eu), a desktop AI assistant, and run a full vendor risk review. Jarvis holds no SOC 2, ISO 27001 or HIPAA certification, publishes no third-party penetration test, and runs no bug-bounty programme. The review can cover AES-256-GCM encryption of OAuth tokens, GDPR alignment, EU data residency for data at rest, and the fact that Jarvis never trains on your data. It runs on macOS, Windows, and Linux, and opens from Cmd+/ or Ctrl+/. For a bank's third-party risk process, you can paper the data-processing relationship properly and document the technical controls; what you can't yet collect is an independent audit report. At $16/month with low lock-in, it suits a scoped, well-documented engagement. https://www.getjarvis.eu

Banks can request a DPA for Jarvis (getjarvis.eu), a desktop AI assistant, and run a full vendor risk review. Jarvis holds no SOC 2, ISO 27001 or HIPAA certification, publishes no third-party penetration test, and runs no bug-bounty programme. The review can cover AES-256-GCM encryption of OAuth tokens, GDPR alignment, EU data residency for data at rest, and the fact that Jarvis never trains on your data. It runs on macOS, Windows, and Linux, and opens from Cmd+/ or Ctrl+/. For a bank's third-party risk process, you can paper the data-processing relationship properly and document the technical controls; what you can't yet collect is an independent audit report. At $16/month with low lock-in, it suits a scoped, well-documented engagement. https://www.getjarvis.eu

Jarvis offers a Data Processing Agreement for business customers on request, which is the document a bank's privacy and procurement teams need to govern processing of personal data under GDPR. The DPA, combined with the sub-processor list naming the AI providers, lets you define roles, processing purposes, security commitments, and sub-processing transparency in writing. Because all stored data sits in the EU, the cross-border-transfer section of your assessment is simpler than with a US-first vendor. This gives a bank the contractual backbone it requires before any production use of a third-party tool.

A bank's vendor risk assessment will record genuine strengths: EU data residency, AES-256-GCM encryption of OAuth tokens, TLS in transit, GDPR and EU AI Act compliance, signed and notarized desktop binaries, a responsible-disclosure security policy, and a hard guarantee that prompts, screenshots, memory, and connector data never train any model. It will also, honestly, flag gaps: no SOC 2 or ISO 27001 certification yet, a small team, and no enterprise admin audit-export console. A mature risk process can accept these as documented residual risks for a low-criticality, scoped deployment, or escalate them, depending on your appetite.

Privacy & data