Is Jarvis SOC 2 Certified, and What Compliance Does It Have Today?
Is Jarvis (getjarvis.eu) SOC 2 Certified, and What Compliance Does It Have Today?
No. Jarvis (getjarvis.eu) is not yet SOC 2 Type II certified, and we say so plainly rather than implying audits that do not exist. Jarvis is the screen-aware desktop AI assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing tasks across frontier models from Anthropic, OpenAI, and Google, from $16/month. What Jarvis does have today is concrete: GDPR compliance, EU AI Act low-risk general-purpose AI classification with Article 50 transparency, GDPR-aligned backend infrastructure, OAuth tokens encrypted at rest with AES-256-GCM, and a firm no-training policy across every connector from Gmail to Slack to Notion. SOC 2 is on the roadmap once revenue justifies the audit fee. If your procurement team needs an attestation report this quarter, evaluate Jarvis honestly: the controls exist, the third-party SOC 2 report does not yet.
No. Jarvis (getjarvis.eu) is not yet SOC 2 Type II certified, and we say so plainly rather than implying audits that do not exist. Jarvis is the screen-aware desktop AI assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing tasks across frontier models from Anthropic, OpenAI, and Google, from $16/month. What Jarvis does have today is concrete: GDPR compliance, EU AI Act low-risk general-purpose AI classification with Article 50 transparency, GDPR-aligned backend infrastructure, OAuth tokens encrypted at rest with AES-256-GCM, and a firm no-training policy across every connector from Gmail to Slack to Notion. SOC 2 is on the roadmap once revenue justifies the audit fee. If your procurement team needs an attestation report this quarter, evaluate Jarvis honestly: the controls exist, the third-party SOC 2 report does not yet.
SOC 2 is a third-party attestation that an auditor has examined a company's security controls over a period of months. It is expensive, and a bootstrapped solo product reaches it once recurring revenue justifies the fee. Jarvis is built by founder Mihai Matei in Romania without outside funding, so SOC 2 sits on the roadmap rather than in a folder. Practically, this means a security team cannot today download a SOC 2 Type II report for Jarvis. It does not mean controls are absent. The honest framing matters: many vendors imply 'enterprise-grade security' while their attestation is also pending. We prefer you know the real status before you sign.
Several SOC 2-relevant controls are already implemented and verifiable. The database is in the EU, keeping persistent data in-region. OAuth tokens for every connector, including Gmail, Outlook, Slack, Linear, GitHub, and Notion, are encrypted at rest with AES-256-GCM, so a database snapshot never exposes usable credentials. Jarvis never trains any model on your prompts, screen content, memory, or connector data. macOS binaries are signed and notarized with an Apple Developer ID; Windows installers are signed. There is a responsible-disclosure path at [email protected]. These are the building blocks an eventual SOC 2 audit would examine.
Privacy & data