PURSOR

Security

Pursor asks to read your email, which is an unusual thing to be asked. This page sets out exactly what that means — what we can reach, what we keep, who can see it, and what happens to it. Everything below can be checked against your own Microsoft admin center or a vendor’s published policy. Where something is not true yet, it says so.

Nobody at Pursor can read your mailbox

There is no screen at Pursor that shows a customer’s inbox, and no way to search one. The connection we hold is not a key to a mailbox — it works only through Microsoft, only for the specific person who granted it, and only for new mail arriving in their own inbox.

The one human step in the product is review of detected commitments: a short sentence such as “Marketing has retained Acme Creative,” with the amount and the date. That is what a person at Pursor sees. It is deliberate — an early customer gets a human checking the work — and it is the whole of it.

What we store, and what we throw away

Most email is not a financial commitment. Newsletters, threads, receipts, scheduling — the overwhelming majority of what passes through a mailbox. For any email that is not a commitment, we keep nothing but an identifier so we do not read it a second time. No subject line, no sender, no text, not a word of it.

When something is a commitment, we keep the sentence describing it, the amount and dates, and up to 500 characters of the email as the evidence behind it — so the person who made the commitment can see what we based it on and correct us. We never store the full email, attachments, or your mailbox history.

We do not copy your mailbox, we do not build a searchable archive of your mail, and we do not read anything that arrived before you connected.

The AI is not trained on your data

Pursor uses Anthropic’s Claude through its commercial API to read an email and decide whether it implies a future payment. Anthropic states that, by default, it does not use inputs or outputs from its commercial products to train its models. We have not opted in to any feedback or training mechanism, and we never will.

The model has no memory between requests. Each email is judged on its own and nothing is retained by the model afterwards — it is not learning your business, your vendors, or your people. Anything Pursor remembers is written deliberately by us into our own database, and you can read it.

Consent is per person, and reversible

Every permission Pursor holds is delegated. That is a specific thing in Microsoft’s model: it means the app can only ever act for a person who has personally signed in and agreed. Pursor holds no application permissions at all — nothing that would let it reach a mailbox on its own authority.

An administrator approving Pursor for the organisation is not handing over anyone’s email. It permits employees to connect if they choose to. Someone who never connects is never read.

  • Anyone connected can stop Pursor reading their mailbox at any moment, without asking IT and without leaving the product.
  • An administrator can revoke the organisation’s approval under Enterprise applications → Pursor → Permissions, at which point every connection stops.
  • If Pursor picks up something personal, one reply deletes it — the item and the stored excerpt are removed from the database, not flagged as hidden.

Nothing is shared without the sender’s approval

A commitment Pursor detects is shown first to the person whose email it came from. It reaches the CEO, CFO or controller only after that person has approved it. If they do not reply, the weekly report says a question is open with them and nothing more — not the subject, not the counterparty, not the amount.

This is the rule the product is built around: Pursor is not a monitoring tool, and it does not report on people.

How it is protected

  • Microsoft access tokens are encrypted with AES-256-GCM before they are stored, under a key held outside the database.
  • All traffic runs over TLS. Data is encrypted at rest by our database provider.
  • Every customer’s data is scoped to their organisation at the query level.
  • We never ask for, hold, or store a Microsoft password. Sign-in happens entirely on Microsoft’s own pages.

Who else is involved

Four vendors touch the service, and no others: Microsoft (your mail, via Graph), Anthropic (reading an email to judge it), Neon (the database), and Vercel (hosting). We do not sell data, we do not share it with anyone else, and there is no advertising or analytics product anywhere near your mail.

What we cannot claim yet

Pursor is early, and a security page that implies otherwise is not worth reading. We do not hold SOC 2, ISO 27001 or any other certification, and we will not pretend a policy document is the same thing.

What we can offer instead is a small surface and a short list: four permissions, four vendors, no application permissions, and a company that answers the phone. If your assessment needs more than that today, we would rather you told us than found out later.

Reviewing Pursor for your organisation? The administrator page lists every permission we request, in Microsoft’s own words.