MyJarvis
Security

The honest version.

What we touch, where it lives, what we delete. Updated as our posture matures.

01

Your data stays in your accounts.

We never copy your documents, emails, or CRM data into a MyJarvis-controlled database. Skills, MCPs, and automations execute against your accounts — Anthropic, your tools, your storage. We have no central data lake.

02

Credentials we touch.

During a deployment we configure your Claude environment and the MCP credentials it uses. We use 1Password sharing or your secrets manager — never plaintext, never email. Once handover is complete, you rotate them.

03

What lives on our infrastructure.

The MCPs we host (MyJarvis Voice, MyJarvis Memory) run on Vercel and Supabase in the EU and US. They process your requests transactionally and don't retain content beyond what's needed for the response.

04

Anthropic is the model layer.

Every model call goes to Anthropic's API. Anthropic's data policy applies: API content is not used for training. Read their full privacy and trust documentation at anthropic.com.

05

Right to deletion.

Ask, and we wipe everything we hold about you within 30 days. Your Claude environment is yours — we have no lock-in.

06

Compliance posture.

We're a small operator-led team. We're not SOC 2 certified yet. If you need a formal audit before engaging, tell us in the audit call — we'll either complete the questionnaire or recommend a partner who has the cert.

Questions

Got a security deal-breaker?

Bring it up in the audit. We'll either solve it, refer you to a certified partner, or be honest that we're not the right fit yet.