Pursor reads. It does not write.
Every connection Pursor holds is read-only, and the agents cannot move money, pay a bill, post an entry, change a record or send anything from your systems. Where a connection is granted by scope, as with a spend platform, the write scopes are not requested, so they are not there to be misused. Where a system offers no read-only mode, Pursor uses a named user whose permissions you set, and nothing is written under it.
When an agent concludes that something should change, the change is a numbered step for a person, naming the record and who owns it. A person does it, in the system, with their own login.
You hold the keys
Banks connect through Plaid. You go through the bank’s own login in the Plaid window; Pursor never sees, holds or stores a bank credential, and the connection can be removed from both Plaid and Pursor in one step.
Spend platforms and ERPs connect through their own APIs. On Ramp, the credential belongs to an app you create in your own Ramp account, with the permissions listed on your own screen; revoking it there ends the connection. On the ERP, Pursor is a user you created and can disable.
There is no shared master credential. Each connection is yours, and each can be cut without asking us.
What we store, and what we throw away
Pursor keeps what the agents work from: bank balances and transactions, card charges, open bills and purchase orders, the forecast, and the answers people give (which payment settled which order, who owns which card). It keeps the reasoning behind each finding, so a person can see how it knew and correct it.
It does not keep documents it does not need, does not copy your ERP, and does not build anything that could be mistaken for a second set of books. Your ledger stays your ledger.
The AI is not trained on your data
Pursor uses Anthropic’s Claude through its commercial API to read a document and decide what it means. Anthropic states that, by default, it does not use inputs or outputs from its commercial products to train its models. We have not opted in to any feedback or training mechanism, and we never will.
The model has no memory between requests. Each call is one document and what Pursor already knows, and nothing is retained by the model afterwards. Anything Pursor remembers about your business is written deliberately into our own database, and you can read it.
Who sees it
Your own people, as you decide. Your accounting firm, if you put one on the account. Your account manager at Pursor, who implements the agents and reviews what they hand up. Nobody else.
Every customer’s data is scoped to their company at the query level. A firm sees the clients it has been attached to and no others.
How it is protected
- Connection tokens are encrypted with AES-256-GCM before they are stored, under a key held outside the database.
- All traffic runs over TLS. Data is encrypted at rest by our database provider.
- Pursor never asks for, holds or stores a password to any of your systems. Your bank, your ERP and your spend platform are reached through their own connection flows, never by a login you hand over.
- Billing is by bank debit through Stripe. Pursor never sees your bank account number.
Who else is involved
Plaid (bank connections), Anthropic (the model), Neon (the database), Vercel (hosting), Stripe (billing) and Postmark (the emails Pursor sends). Plus the systems you connect, through their own APIs. We do not sell data, we do not share it with anyone else, and there is no advertising or analytics product anywhere near it.
When you leave
Disconnecting a source removes the connection at both ends. Closing the account deletes what Pursor holds about the company. It is a button, not a support ticket, and it does not need our permission.
Certification
Pursor does not yet hold SOC 2 or ISO 27001. Independent audit is planned, and the report will be published on this page when it exists. We will not describe a policy document as a certification in the meantime.
Until then, everything above is checkable without taking our word for it: the scopes on your own developer console, the connection screens, and the vendors’ published policies. If your assessment needs more than that today, we would rather you told us than found out later.