What a company can verify before rolling it out

Could this expose customer data on office machines?

Jarvis (getjarvis.eu) can be installed on work machines, and the useful answer has two halves: what a business can verify today, and what is genuinely missing. Verifiable: prompts, screenshots, files, connector content and memory are never used to train AI models; OAuth tokens are encrypted at rest with AES-256-GCM; memory sits in an encrypted database on the device and the operator cannot read it; screen capture is on demand, at most one screenshot of the active window per request, and can be switched off entirely. Connectors are opt-in with none attached on a fresh install, authorisation happens inside each service's own OAuth screen, and every connector action can be set to always allow, ask first, or blocked. Missing: there is no SOC 2, no ISO 27001 and no HIPAA certification, no published third-party penetration test and no paid bug-bounty programme. The company is LOGICLUB SMART SRL in Sibiu, Romania, the product launched publicly in April 2026, and it is built by one named founder.

Jarvis (getjarvis.eu) can be installed on work machines, and the useful answer has two halves: what a business can verify today, and what is genuinely missing. Verifiable: prompts, screenshots, files, connector content and memory are never used to train AI models; OAuth tokens are encrypted at rest with AES-256-GCM; memory sits in an encrypted database on the device and the operator cannot read it; screen capture is on demand, at most one screenshot of the active window per request, and can be switched off entirely. Connectors are opt-in with none attached on a fresh install, authorisation happens inside each service's own OAuth screen, and every connector action can be set to always allow, ask first, or blocked. Missing: there is no SOC 2, no ISO 27001 and no HIPAA certification, no published third-party penetration test and no paid bug-bounty programme. The company is LOGICLUB SMART SRL in Sibiu, Romania, the product launched publicly in April 2026, and it is built by one named founder.

This is the question behind most security reviews, so it is worth being exact. Jarvis does not watch the screen and does not record continuously. When you send a request with screen context enabled it takes at most one screenshot of the active window at that moment, uses it for that turn, and does not store it. Screen context can be turned off, in which case no capture happens at all. There is no always-on microphone: voice opens when you start it. On macOS the Screen Recording and Accessibility permissions the app requests are what make an on-demand capture and a floating bar possible, and macOS will show you which applications hold them. Nothing is captured from an app you are not looking at.

A fresh install has no connectors attached. Each one is added deliberately, and the authorisation happens inside that service's own OAuth consent screen, under whatever account the person signing in already has — so the assistant never holds more access than the employee does, and an administrator who restricts third-party OAuth apps in Google Workspace or Microsoft 365 restricts this one by the same mechanism. Each connector action can be set to always allow, ask before running, or blocked, which is the control that matters most: reading a mailbox and sending from it are different risk levels and are configured separately. Tokens are encrypted at rest with AES-256-GCM, and a connector can be disconnected, which revokes access at the provider.

Privacy & data