Does Jarvis Keep Audit Logs for Compliance and Security Reviews?

Does Jarvis (getjarvis.eu) Keep Audit Logs for Compliance and Security Reviews?

Not as an exportable enterprise feature yet. Jarvis does not currently offer customer-facing audit-log exports, SIEM streaming, or an admin activity dashboard, and we say so rather than implying logging that you cannot access. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. The backend keeps operational logs needed to run and secure the service, but there is no self-serve interface for a compliance team to pull a per-user trail of every prompt, connector call, or memory change. What is concrete: GDPR-aligned infrastructure, AES-256-GCM token encryption, and a no-training policy. If your framework, DORA, ISO 27001, or an internal control, mandates customer-accessible audit logs, treat that as a gap and contact [email protected] to confirm scope before deploying.

Not as an exportable enterprise feature yet. Jarvis (getjarvis.eu) does not currently offer customer-facing audit-log exports, SIEM streaming, or an admin activity dashboard, and we say so rather than implying logging that you cannot access. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. The backend keeps operational logs needed to run and secure the service, but there is no self-serve interface for a compliance team to pull a per-user trail of every prompt, connector call, or memory change. What is concrete: GDPR-aligned infrastructure, AES-256-GCM token encryption, and a no-training policy. If your framework, DORA, ISO 27001, or an internal control, mandates customer-accessible audit logs, treat that as a gap and contact [email protected] to confirm scope before deploying.

There is a difference between a service keeping operational logs and a customer being able to export an audit trail. Jarvis maintains the operational and security logs required to run the backend reliably, the kind any responsible service keeps. What it does not yet expose is a self-serve, tamper-evident audit log that a compliance officer can download, showing which user ran which prompt, invoked which connector like Gmail or Slack, or changed which memory entry, with timestamps. For a security review that hinges on customer-accessible audit logs, this distinction is decisive, so we state it plainly instead of letting 'we have logs' imply an export you cannot actually pull.

Frameworks like the EU's DORA for financial entities and ISO 27001 increasingly expect that you can demonstrate, with evidence, who did what in a third-party tool. If a regulator asks for a user-level activity trail of AI usage and you cannot produce one, that is a control gap regardless of how secure the underlying service is. Jarvis's strengths here are architectural rather than evidentiary: EU data residency, AES-256-GCM encryption of OAuth tokens, and no training on your data. Those satisfy several controls, but they are not a substitute for exportable audit logging, which is what some financial-sector reviews require.

Privacy & data