← Trust Directory

Grammarly

grammarly.com · 1 assessment

Grammarly - organisation
Security review required
1 blocking issue to resolve before signing
Assessed Oct 5, 2026 · public evidence coverage 55% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2 Type 2
Vendor claimed only

Security, privacy, availability and confidentiality trust services criteria; report available on request from sales.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
SOC 3
Vendor claimed only

Security, privacy, availability and confidentiality; described as a public report.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 27001:2022
Claimed, scope unclear

ISMS certification claimed; certificate linked but issuer, certified scope and validity not stated on the page.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 27017:2015
Claimed, scope unclear

Cloud services controls claimed; issuer and validity not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 27018:2019
Claimed, scope unclear

PII protection in the cloud claimed; issuer and validity not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 27701:2019
Claimed, scope unclear

Privacy information management system claimed; issuer and validity not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 42001:2023
Claimed, scope unclear

AI management system certification claimed for 'responsible AI development and use'; certified scope, issuer and validity not stated.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
EU-US Data Privacy Framework (with UK Extension and Swiss-US DPF)
Vendor claimed only

Transfers of EU, UK and Swiss personal data to the US; registry-checkable at dataprivacyframework.gov but not verified in this scan.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
HIPAA
Vendor claimed only

Self-asserted compliance, not a third-party attestation; PHI may only be processed under a signed Business Associate Agreement.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
CSA STAR Level 2
Claimed & corroborated
  • ✓ Vendor claimed
  • ✓ Evidence cited
  • ✓ Registry corroborated
  • — Scope verified
  • — Current

Verified on the registry · CSA STAR Registry · checked Oct 5, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

Infrastructure: Amazon Web Services (US East region)

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.