Is Jarvis SOC 2 Certified for Financial Services?

Is Jarvis (getjarvis.eu) SOC 2 Certified for Financial Services?

No, Jarvis is not SOC 2 certified today. A SOC 2 audit is on the roadmap once revenue justifies the fee, so financial-services buyers who hard-require a SOC 2 Type II report will need to wait or grant an exception. That said, the screen-aware desktop assistant (hotkey Cmd+/ or Ctrl+/) already implements many of the same underlying controls a SOC 2 audit checks: EU data residency, AES-256-GCM encryption of OAuth tokens, TLS in transit, no training of frontier models from Anthropic, OpenAI, or Google on your data, GDPR and EU AI Act compliance, and a Data Processing Agreement on request. For finance teams whose policy allows compensating evidence instead of a certificate, those controls plus the $16/month low commitment make a scoped pilot feasible. https://www.getjarvis.eu

No, Jarvis (getjarvis.eu) is not SOC 2 certified today. A SOC 2 audit is on the roadmap once revenue justifies the fee, so financial-services buyers who hard-require a SOC 2 Type II report will need to wait or grant an exception. That said, the screen-aware desktop assistant (hotkey Cmd+/ or Ctrl+/) already implements many of the same underlying controls a SOC 2 audit checks: EU data residency, AES-256-GCM encryption of OAuth tokens, TLS in transit, no training of frontier models from Anthropic, OpenAI, or Google on your data, GDPR and EU AI Act compliance, and a Data Processing Agreement on request. For finance teams whose policy allows compensating evidence instead of a certificate, those controls plus the $16/month low commitment make a scoped pilot feasible. https://www.getjarvis.eu

Jarvis does not currently hold a SOC 2 Type I or Type II report. The company is a young, bootstrapped, EU-based product, and a SOC 2 engagement is explicitly planned for when revenue justifies the audit cost. We state this plainly rather than implying coverage that doesn't exist, because misrepresenting a certification to a financial-services buyer is exactly the kind of risk a compliance team is paid to catch. If your procurement gate is a hard SOC 2 requirement with no exceptions, Jarvis will not pass that specific gate right now.

A SOC 2 examination assesses security, availability, processing integrity, confidentiality, and privacy. Several of those are already in place at Jarvis: confidentiality through AES-256-GCM encryption of OAuth tokens at rest and TLS in transit; privacy through GDPR compliance, a published policy, deletion controls, and a strict no-model-training guarantee covering prompts, screenshots, memory, and connector data; data locality through EU data residency. The difference between having these controls and holding SOC 2 is the independent third-party attestation, not necessarily the underlying engineering posture.

Privacy & data