Security

Pursor asks to connect to your bank, your cards, your spend platform and your ERP, which is a reasonable thing to be careful about. This page sets out exactly what that means: what we can reach, what we can do with it, what we keep, who else is involved, and what happens when you leave. Where something is not true yet, it says so.

Pursor reads. It does not write.

Every connection Pursor holds is read-only, and the agents cannot move money, pay a bill, post an entry, change a record or send anything from your systems. Where a connection is granted by scope, as with a spend platform, the write scopes are not requested, so they are not there to be misused. Where a system offers no read-only mode, Pursor uses a named user whose permissions you set, and nothing is written under it.

When an agent concludes that something should change, the change is a numbered step for a person, naming the record and who owns it. A person does it, in the system, with their own login.

You hold the keys

Banks connect through Plaid. You go through the bank’s own login in the Plaid window; Pursor never sees, holds or stores a bank credential, and the connection can be removed from both Plaid and Pursor in one step.

Spend platforms and ERPs connect through their own APIs. On Ramp, the credential belongs to an app you create in your own Ramp account, with the permissions listed on your own screen; revoking it there ends the connection. On the ERP, Pursor is a user you created and can disable.

There is no shared master credential. Each connection is yours, and each can be cut without asking us.

What we store, and what we throw away

Pursor keeps what the agents work from: bank balances and transactions, card charges, open bills and purchase orders, the forecast, and the answers people give (which payment settled which order, who owns which card). It keeps the reasoning behind each finding, so a person can see how it knew and correct it.

It does not keep documents it does not need, does not copy your ERP, and does not build anything that could be mistaken for a second set of books. Your ledger stays your ledger.

The AI is not trained on your data

Pursor uses Anthropic’s Claude through its commercial API to read a document and decide what it means. Anthropic states that, by default, it does not use inputs or outputs from its commercial products to train its models. We have not opted in to any feedback or training mechanism, and we never will.

The model has no memory between requests. Each call is one document and what Pursor already knows, and nothing is retained by the model afterwards. Anything Pursor remembers about your business is written deliberately into our own database, and you can read it.

Who sees it

Your own people, as you decide. Your accounting firm, if you put one on the account. Your account manager at Pursor, who implements the agents and reviews what they hand up. Nobody else.

Every customer’s data is scoped to their company at the query level. A firm sees the clients it has been attached to and no others.

How it is protected

  • Connection tokens are encrypted with AES-256-GCM before they are stored, under a key held outside the database.
  • All traffic runs over TLS. Data is encrypted at rest by our database provider.
  • Pursor never asks for, holds or stores a password to any of your systems. Your bank, your ERP and your spend platform are reached through their own connection flows, never by a login you hand over.
  • Billing is by bank debit through Stripe. Pursor never sees your bank account number.

Who else is involved

Plaid (bank connections), Anthropic (the model), Neon (the database), Vercel (hosting), Stripe (billing) and Postmark (the emails Pursor sends). Plus the systems you connect, through their own APIs. We do not sell data, we do not share it with anyone else, and there is no advertising or analytics product anywhere near it.

When you leave

Disconnecting a source removes the connection at both ends. Closing the account deletes what Pursor holds about the company. It is a button, not a support ticket, and it does not need our permission.

Certification

Pursor does not yet hold SOC 2 or ISO 27001. Independent audit is planned, and the report will be published on this page when it exists. We will not describe a policy document as a certification in the meantime.

Until then, everything above is checkable without taking our word for it: the scopes on your own developer console, the connection screens, and the vendors’ published policies. If your assessment needs more than that today, we would rather you told us than found out later.

Need this in a form for a security review? Ask and the account manager will fill it in with you.