Jarvis
A private AI company with one client: it remembers, plans, acts within permission, checks its own work and reports back.
- Product, architecture, AI-assisted build
- 2026
- Python 3.12, SQLite, SQLAlchemy, FastAPI, OpenRouter, Next.js, Tailwind

Context
Most personal AI tools are chat windows: they answer, then forget. I wanted something that runs my work the way a small company would, with memory, a task list that understands dependencies, and the judgement to ask before doing anything that matters.
Jarvis is that company. It has exactly one client, me, and it is also the most complete thing I have built.
The problem
Language models are good at proposing and bad at being trusted. A system that sends messages or spends money on its own has to stay predictable, reversible and accountable, even on the days the model is wrong.
The approach
State lives in a database, not in prompts. Agents propose; deterministic code decides and executes. Every request travels the same path: it is ingested as an event, becomes tasks with dependencies, and any action a model proposes goes through policy, and through approval when the risk requires it, before an executor runs it and verifies the result. Everything is written to an audit log.
The whole core runs end to end with no API key, no Telegram and no internet, which made it possible to test every rule before a real model was attached.
How a request travels
Drawn on the hexagonal lattice of ice. The warm point is the one place a human is asked.
- Transport
- Ingest
- Events
- Tasks + deps
- Proposed action
- Policy
- Approval
- Executor
- Audit + outbox
Decisions that shaped it
Risk tiers and approvals
Every action is a typed verb with a risk tier. A ten-step policy engine decides whether it runs, waits for approval or is refused. An approval that nobody answers expires into a denial, never into a yes.
One way out
People are only ever contacted through a single outbox, so nothing reaches anyone by accident. A kill switch stops everything at once.
Dependencies that explain themselves
When a task is blocked, for example on a voice sample only a human can record, Jarvis creates a task for me and says exactly what would unblock the original one.
Memory that understands Persian
Full-text search normalises Arabic and Persian keyboard variants, so the same word typed two different ways is still found.
Cost is part of the state
A cost ledger and budget modes (normal, degraded, restricted, frozen) sit in front of every model call. The model layer routes through OpenRouter with a fallback model when the primary one fails.
An audit you can verify
The audit log is append-only and hash-chained with SHA-256: if any past record were altered, verification would fail.
Screens



Where it stands
- Core runtime, dependency engine, policy and approvals, memory, audit, cost ledger and ops console: Python 3.12, SQLite, 161 automated tests.
- Real model layer, live since 26 September 2026 (OpenRouter, with a fallback model).
- Interface direction: a Next.js prototype of the command center. It shows demo data and is not yet connected to the core.
- Text capture end to end, and a read-only bridge to my notes vault.
- Voice, Telegram, calendar, connecting the interface to the core, and deployment.
What I learned
The interesting part of an AI system is not the model. It is everything around it that decides what the model is allowed to do, and an honest record of what it did.