Security
Your deals don't train anyone's model.
Pursuit runs on Anthropic's Claude API under commercial terms: your deals are not used to train models under those terms. Every request is authenticated and scoped to your account, so you only ever see your own deals. Delete any deal at any time. If you cancel, your data stays available read-only for 90 days — export everything with one click — then it's permanently deleted.
Source discipline
Six guardrails. Built in, not bolted on.
Six guardrails ensure Pursuit's output can be trusted at Investment Committee level. By construction, not by policy.
Document-grounded extraction
Every figure originates from a submitted document. The AI does not infer or hallucinate values.
Source citation behind every number
Every value cites a document name and page number. The verbatim snippet is preserved alongside the parsed value.
Red flag on unsourced data
Fields the AI cannot confirm are flagged, not filled with estimates. The analyst decides what to use.
loan_amount → NOT FOUND · FLAGGEDAnalyst review before export
The model is a working draft, not an auto-final deliverable. Every deal requires analyst review before export. Gap flags are visible, not suppressed.
Per-run audit log
Every agent run is logged with the acting user and a timestamp, so any output can be traced back to who ran it and when.
Public-data cross-check
If two public sources contradict each other, Pursuit flags the discrepancy rather than guessing which to use.
How your data is protected
Your deals are yours alone.
There is no shared pool of deals. Every time the app touches your data, it checks that the request belongs to your account — so you only ever see your own deals, and no one else can see them.
Which AI runs your deals
Underwriting runs on Anthropic's Claude models via their commercial API. Under Anthropic's commercial terms, your documents and outputs are not used to train models.
Your account, and only your account
Every time the app fetches a deal, it confirms the request is coming from you. Another customer's login can never reach your deals — that check runs on every request, not just at sign-in.
Staying logged in, safely
Your session is tied to a random token that we store only in scrambled form — never in a way anyone could read and reuse. Too many wrong password attempts and the account locks.
The keys stay on our servers
The keys that let Pursuit run the AI live on our servers, never in your browser, and are stripped out of our logs so they can't leak.
Encrypted on the way and at rest
Everything sent between you and Pursuit is encrypted, so it can't be read in transit. Your uploaded files are also encrypted while stored (AES-256), so they're unreadable even at rest.
Delete on demand
Delete any deal at any time. If you cancel, your data stays available read-only for 90 days — export everything with one click — then it's permanently deleted.
Defenses against documents that try to trick the AI
Some documents hide instructions inside them to trick an AI into doing something it shouldn't (called prompt injection). Pursuit fences off every uploaded file so hidden instructions can't hijack a run.
Compliance
Standards, stated honestly.
Only what is true today is marked Live. Anything not yet in place is marked Planned. No badge we have not earned.
SOC 2 Type I, then Type II
SOC 2 readiness is in progress: Type I first, then Type II. There is no report yet. We will share the report when the audit is complete.
Data privacy
Designed to support deletion, export, and retention requests (CCPA/GDPR-style rights). Delete any deal at any time. Your deals are not used to train models under our Anthropic commercial terms.
Payments via Stripe
Payments run through Stripe Checkout. Card data never touches our servers, and we do not store cardholder data. Stripe, a PCI-compliant processor, handles all card data.
Compliance status
Every control, with an honest Live or Planned status.
| Control | Status |
|---|---|
| Per-request authentication and account scoping | Live |
| Random, hashed session tokens and login lockout | Live |
| Secrets held server-side and redacted from logs | Live |
| Per-agent-run audit log (acting user and timestamp) | Live |
| Encryption in transit (TLS, HSTS, Secure cookies) | Live |
| Delete on demand; 90-day read-only export window after cancel | Live |
| Prompt-injection mitigations on uploaded documents | Live |
| Deals not used to train models (Anthropic commercial terms) | Live |
| Payments via Stripe, no card data on our servers | Live |
| Deletion, export, and retention support (CCPA/GDPR-style rights) | Live |
| Files encrypted at rest (AES-256-GCM) | Live |
| SOC 2 Type I, then Type II report | Planned |
| Team roles and role-based access control | Planned |
Get started
Security built in. Ready to use.
Request access and get a live walkthrough of the source-discipline system.