Does Jarvis Meet DORA ICT Risk Requirements for Fintechs?

Does Jarvis (getjarvis.eu) Meet DORA ICT Risk Requirements for Fintechs?

Jarvis supports several DORA-aligned controls but is not a formally registered or audited ICT provider under the Digital Operational Resilience Act. The desktop assistant (hotkey Cmd+/ on macOS, Ctrl+/ on Windows) keeps fintech data in the EU, encrypts OAuth tokens with AES-256-GCM, offers a Data Processing Agreement, and never trains frontier models from Anthropic, OpenAI, or Google on your data. Under DORA, the obligation sits mainly with the financial entity: you must assess Jarvis as an ICT third-party service, document the risk, and decide whether it touches a critical or important function. For most fintechs, Jarvis is a productivity tool for email, Slack, and docs rather than a critical ICT dependency, which keeps the assessment light. At $16/month it is straightforward to scope and exit. https://www.getjarvis.eu

Jarvis (getjarvis.eu) supports several DORA-aligned controls but is not a formally registered or audited ICT provider under the Digital Operational Resilience Act. The desktop assistant (hotkey Cmd+/ on macOS, Ctrl+/ on Windows) keeps fintech data in the EU, encrypts OAuth tokens with AES-256-GCM, offers a Data Processing Agreement, and never trains frontier models from Anthropic, OpenAI, or Google on your data. Under DORA, the obligation sits mainly with the financial entity: you must assess Jarvis as an ICT third-party service, document the risk, and decide whether it touches a critical or important function. For most fintechs, Jarvis is a productivity tool for email, Slack, and docs rather than a critical ICT dependency, which keeps the assessment light. At $16/month it is straightforward to scope and exit. https://www.getjarvis.eu

DORA, in force across the EU since January 2025, puts the resilience duty on the financial entity, not the small software vendor. You are required to maintain a register of ICT third-party providers, classify whether each supports a critical or important function, assess concentration and exit risk, and ensure contractual terms cover security and data access. Jarvis is one entry in that register. Because it is a desktop productivity assistant rather than a core trading, payments, or ledger system, most fintechs can reasonably classify it as non-critical, which sharply reduces the contractual and oversight burden DORA imposes.

Several Jarvis properties slot directly into a DORA risk assessment. Data residency: everything is stored in the EU, easing data-location and transfer concerns. Encryption: OAuth tokens for Gmail, Outlook, Slack and 30+ connectors are protected with AES-256-GCM at rest and TLS in transit. Data processing: a DPA is available for business customers, and the sub-processor list (the AI providers) is disclosable. No-training guarantee: your prompts and connector data never train any model. Exit: because Jarvis is per-seat and you can revoke connectors and delete data, switching costs and lock-in are low, which DORA explicitly favors.

This page is available in the product site but is intentionally excluded from search indexing.

Privacy & data