Grammarly

grammarly.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
56 / 100C
Procurement decision
Security review required
4 conditions outstanding
  • Training on user content is default-on for individual accounts; business exclusions are unspecific and enterprise terms are not public
  • No formal subprocessor register disclosed
  • No clear commitment that your data will not train their models

+1 more

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Training on user content is default-on for individual accounts; business exclusions are unspecific and enterprise terms are not publicBlocking

Why it matters: The Trust Center and the Superhuman privacy policy both state user content is used to train models unless the account holder turns off a training setting, and the public Terms licence User Content for improving the Services including training the suggestion engine. Grammarly states content from 'certain business users' and EU/UK-originating accounts is excluded automatically, but does not say which plans qualify. Enterprise-Tier Services and Organization accounts are governed by a Customer Business Agreement and data protection terms that are not in the scanned material.

What to ask for: Confirm in writing which plans (Grammarly Business, Enterprise, Education, Superhuman team plans) are excluded from model training by default, whether the Customer Business Agreement and Data Privacy Addendum prohibit training on customer content outright, and whether the exclusion also covers your third-party AI providers.

Evidence
“You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone. To do so, turn off Product Improvement and Training in your account settings.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“All users have the ability to opt out of allowing Grammarly to use their content to improve its products or train its models . We do not train on any content from certain business users or users whose accounts originate in the EU or UK, automatically.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Develop and improve AI. We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“One of the most important pillars of responsible AI is upholding privacy and security to protect all users, customers, and their companies’ reputations. We do not allow our third-party service providers to train their models on user content.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“These Terms do not apply to our various enterprise-tier products and services, which are provided as subscriptions through our enterprise sales team to organizations (collectively, the “Enterprise-Tier Services”). If your organization has purchased the Enterprise-Tier Services, the governing terms and conditions will be our Customer Business Agreement .”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“If you open an Account on behalf of an Entity, we will process your personal information and that of the end users of that Account in accordance with our Data Privacy Addendum, and we and you agree to comply with its terms, as applicable.”
No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
“You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone. To do so, turn off Product Improvement and Training in your account settings.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“All users have the ability to opt out of allowing Grammarly to use their content to improve its products or train its models . We do not train on any content from certain business users or users whose accounts originate in the EU or UK, automatically.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Develop and improve AI. We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“One of the most important pillars of responsible AI is upholding privacy and security to protect all users, customers, and their companies’ reputations. We do not allow our third-party service providers to train their models on user content.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);”
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
“Please note that if you save a document in the Grammarly Editor, we’ll store it until you delete the document or your Grammarly account.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“We retain personal data for as long as necessary to provide our products to you, to complete the transactions you have requested, to comply with our legal obligations, to resolve disputes, and for other legitimate business purposes. We retain the data we collect for different periods of time depending on what it is, how it’s used, and how you configure your settings.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

User content is used to train Grammarly's models and improve the product by default; the user must turn off the Product Improvement and Training setting in account settings to opt out.

Requires written confirmation — see Before you sign ↓

Evidence
“You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone. To do so, turn off Product Improvement and Training in your account settings.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“All users have the ability to opt out of allowing Grammarly to use their content to improve its products or train its models . We do not train on any content from certain business users or users whose accounts originate in the EU or UK, automatically.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Develop and improve AI. We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“One of the most important pillars of responsible AI is upholding privacy and security to protect all users, customers, and their companies’ reputations. We do not allow our third-party service providers to train their models on user content.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);”
!How long do they keep your data?Ask the vendor

Documents saved in the Grammarly Editor are retained until the user deletes the document or the account; retention is user-controlled with no fixed maximum.

Requires written confirmation — see Before you sign ↓

Evidence
“Please note that if you save a document in the Grammarly Editor, we’ll store it until you delete the document or your Grammarly account.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“We retain personal data for as long as necessary to provide our products to you, to complete the transactions you have requested, to comply with our legal obligations, to resolve disputes, and for other legitimate business purposes. We retain the data we collect for different periods of time depending on what it is, how it’s used, and how you configure your settings.”
!Who else can access your data?Ask the vendor

Grammarly confirms third-party service providers handle user content, but none of the scanned pages names which AI or LLM providers are in the request path; the only named infrastructure party is Amazon Web Services.

Requires written confirmation — see Before you sign ↓

Evidence
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
!Where is your data processed?Ask the vendor

Grammarly hosts data in Amazon Web Services data centres in the US East region; no regional hosting option is mentioned.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly hosts data in Amazon Web Services data centers in the US East region and ensures continual product availability by using native backup tools. An industry-leading infrastructure provider, AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report.”
!What happens in a security incident?Ask the vendor

Grammarly runs an ongoing HackerOne bug bounty program and publishes a security contact ([email protected]), committing to rapid response and remediation of reported issues; no customer breach-notification timeline is published.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly’s ongoing HackerOne bug bounty program promotes transparency and provides a channel for external security researchers to identify potential security concerns. Our team responds rapidly—and resolves these issues before they can be exploited. If you believe you’ve discovered a security-related issue, please report it at HackerOne or contact us at [email protected].”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“That’s why we undergo third-party network penetration tests as well as AWS security and corporate infrastructure security assessments and audits.”

Email to send the vendor10 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello Grammarly team,

We are assessing Grammarly as part of our supplier review. Before we proceed, please confirm the following in writing:

1. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
2. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
3. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
4. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
5. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
6. How are customers notified of changes to the AI models or model providers behind Grammarly features, and which legal entity and documents govern an enterprise customer after the Superhuman rebrand?
7. Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
8. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
9. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
10. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Unusually broad assurance portfolio including ISO/IEC 42001 and a gated Responsible AI processStrong

Grammarly claims SOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27701 and 42001:2023, states these rest on annual independent audits, and describes a Responsible AI team that risk-categorises every feature and blocks launches until mitigations are in place, backed by automated and human evaluations and red teaming. All of this is vendor-published; no certificate issuer or validity date appears in the scanned pages, so registry verification is still needed.

An AI management system certification (ISO/IEC 42001) alongside the security and privacy ISO set and a described launch gate is more than most hosted AI vendors publish, and gives a buyer concrete artefacts to request and verify.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“The RAI team is involved in every feature that is shipped. Each feature receives a risk categorization according to criteria developed by our team, and launches are not approved unless the recommended mitigations are implemented.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We have implemented automated measures to evaluate quality, fairness, and safety in our AI products. We aim to resolve any high-severity issues we discover so that they do not appear to our users. Furthermore, we monitor user feedback and regularly conduct human evaluations so we can continually improve our approach.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, much of our security work is focused on preventing adversarial attacks on our users. We rely on a red team of experts with experience on both sides of the security fence to identify adversarial security approaches and vulnerabilities and help us formulate mitigation strategies that help keep our product safe.”
“SOC 2 (Type 2) Grammarly’s SOC 2 (Type 2) report validates our controls based on the security, privacy, availability, and confidentiality trust services criteria. Contact us to read our report.”
“ISO/IEC 27001:2022 Grammarly’s information security management system meets the requirements of ISO 27001 and 27002 international standards. Read our certificate. ISO/IEC 27018:2019 Grammarly meets the requirements of ISO 27018 regarding our protection of personally identifiable information (PII) in the cloud. Read our certificate. ISO/IEC 42001:2023 Grammarly meets the requirements of ISO 42001 ensuring responsible AI development and use.”
“SOC 3 Grammarly’s SOC 3 report describes our validated controls regarding security, privacy, availability, and confidentiality. Read our public report. ISO/IEC 27017:2015 Grammarly’s information security practices meet the requirements of ISO 27017 regarding our provision and use of cloud services. Read our certificate. ISO/IEC 27701:2019 Grammarly's privacy information management system meets the requirements of ISO 27701 international standards.”
“Our certifications are based on comprehensive examinations conducted by independent third-party audit firms each year. You can rely on our certifications if you need them for any vendor risk-management purposes.”
✗Training on user content is default-on for individual accounts; business exclusions are unspecific and enterprise terms are not publicGap

The Trust Center and the Superhuman privacy policy both state user content is used to train models unless the account holder turns off a training setting, and the public Terms licence User Content for improving the Services including training the suggestion engine. Grammarly states content from 'certain business users' and EU/UK-originating accounts is excluded automatically, but does not say which plans qualify. Enterprise-Tier Services and Organization accounts are governed by a Customer Business Agreement and data protection terms that are not in the scanned material.

A buyer cannot tell from public pages whether their plan is in the trained-on population or the excluded one; the answer depends on a contract they have not seen.

Question for vendor: Confirm in writing which plans (Grammarly Business, Enterprise, Education, Superhuman team plans) are excluded from model training by default, whether the Customer Business Agreement and Data Privacy Addendum prohibit training on customer content outright, and whether the exclusion also covers your third-party AI providers.

Evidence
“You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone. To do so, turn off Product Improvement and Training in your account settings.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“All users have the ability to opt out of allowing Grammarly to use their content to improve its products or train its models . We do not train on any content from certain business users or users whose accounts originate in the EU or UK, automatically.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Develop and improve AI. We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“One of the most important pillars of responsible AI is upholding privacy and security to protect all users, customers, and their companies’ reputations. We do not allow our third-party service providers to train their models on user content.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“These Terms do not apply to our various enterprise-tier products and services, which are provided as subscriptions through our enterprise sales team to organizations (collectively, the “Enterprise-Tier Services”). If your organization has purchased the Enterprise-Tier Services, the governing terms and conditions will be our Customer Business Agreement .”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“If you open an Account on behalf of an Entity, we will process your personal information and that of the end users of that Account in accordance with our Data Privacy Addendum, and we and you agree to comply with its terms, as applicable.”
!AI and LLM providers in the request path are not namedGap

Grammarly says it trains its own models and designs prompts for large language models, and that third-party service providers (described only as 'AI technology' providers) are restricted from training on user content. No provider is named anywhere in the scanned pages, and no subprocessor list was found. Amazon Web Services (US East) is the only named infrastructure party; enabling a Third-Party Service integration also sends User Content to that provider. Both model_provider_transparency and subprocessors_and_supply_chain are therefore marked partial rather than not_evidenced: the vendor discloses that the chain exists and how it is governed, but not who is in it.

Without named model providers a buyer cannot assess where prompts and documents travel, which jurisdiction the LLM inference runs in, or whether the provider's own retention applies.

Question for vendor: Provide the current subprocessor list naming every AI model provider that receives customer content, the hosting region for each, their retention of prompts and outputs, and how customers are notified when a provider is added or changed.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly hosts data in Amazon Web Services data centers in the US East region and ensures continual product availability by using native backup tools. An industry-leading infrastructure provider, AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
!Vulnerability handling is well evidenced but no breach-notification commitment is publishedGap

Grammarly publishes a HackerOne bug bounty, a security contact address, third-party penetration testing and infrastructure security audits. The scanned pages contain no commitment on customer notification of security incidents or data breaches (timeline, channel, content). vulnerability_and_incident_handling is marked partial: the vulnerability half is covered; the incident-notification half, which a hosted SaaS vendor can and should disclose, is absent from the public material and presumably sits in the unpublished Data Privacy Addendum.

Breach-notification obligations drive a buyer's own regulatory timelines (for example GDPR 72 hours, Australian NDB); a bug bounty does not substitute for them.

Question for vendor: What is your contractual commitment for notifying customers of a confirmed security incident affecting their data, including the maximum notification time and the information provided?

Evidence
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly’s ongoing HackerOne bug bounty program promotes transparency and provides a channel for external security researchers to identify potential security concerns. Our team responds rapidly—and resolves these issues before they can be exploited. If you believe you’ve discovered a security-related issue, please report it at HackerOne or contact us at [email protected].”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“That’s why we undergo third-party network penetration tests as well as AWS security and corporate infrastructure security assessments and audits.”
!Change notice covers terms and features, not AI model changes; corporate rebrand to Superhuman is in progressGap

The Terms give 30 days' notice of changes to the Terms and only 'reasonable efforts' notice before a Services Update that may significantly impair use. Nothing describes how changes to underlying AI models or providers are communicated. The Terms, Acceptable Use Policy and privacy policy are now issued by Superhuman Platform Inc. (formerly Grammarly, Inc.) while the Trust Center, security and compliance pages remain Grammarly-branded, so a buyer must map claims across two names. change_management is marked partial on this basis.

Model or provider swaps can change data flows and output behaviour without any change to the written terms; buyers relying on an evaluation need to know when the evaluated system has changed.

Question for vendor: How are customers notified of changes to the AI models or model providers behind Grammarly features, and which legal entity and documents govern an enterprise customer after the Superhuman rebrand?

Evidence
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“We may modify or discontinue any feature, functionality, or component of our Services at any time (a “ Services Update ”). If we believe a Services Update may significantly impair your use of our Services, we will use reasonable efforts to notify you before making such Services Update by either sending an email to the email address associated with your Account or via an in-product notification.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“If we make changes, we will notify you either by email or through the Services at least thirty (30) days before the changes take effect.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“These Terms do not apply to our various enterprise-tier products and services, which are provided as subscriptions through our enterprise sales team to organizations (collectively, the “Enterprise-Tier Services”). If your organization has purchased the Enterprise-Tier Services, the governing terms and conditions will be our Customer Business Agreement .”
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score65
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“The RAI team is involved in every feature that is shipped. Each feature receives a risk categorization according to criteria developed by our team, and launches are not approved unless the recommended mitigations are implemented.”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly’s in-house team of security specialists is focused on ensuring security across the company—in our product and infrastructure, as well as in all operations. The team also oversees risk management and standards compliance. Company executives are directly involved in overseeing security strategy.”

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score53
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedArtificial Intelligence (AI) at Grammarly ↗retrieved Oct 5, 2026
“Grammarly’s specialized AI agents help turn your thoughts into impact by making sure they’re clear, resonate with your audience, and sound like you.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“Agents respond to prompts, generate new content, and provide intelligent feedback based on your writing. They can draft new text directly into the editor, highlight key sections, and offer suggestions for revision, right within your writing surface.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We have implemented automated measures to evaluate quality, fairness, and safety in our AI products. We aim to resolve any high-severity issues we discover so that they do not appear to our users. Furthermore, we monitor user feedback and regularly conduct human evaluations so we can continually improve our approach.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, much of our security work is focused on preventing adversarial attacks on our users. We rely on a red team of experts with experience on both sides of the security fence to identify adversarial security approaches and vulnerabilities and help us formulate mitigation strategies that help keep our product safe.”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“We may modify or discontinue any feature, functionality, or component of our Services at any time (a “ Services Update ”). If we believe a Services Update may significantly impair your use of our Services, we will use reasonable efforts to notify you before making such Services Update by either sending an email to the email address associated with your Account or via an in-product notification.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“If we make changes, we will notify you either by email or through the Services at least thirty (30) days before the changes take effect.”

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: vendor-evidenced, not yet independently corroborated.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“At Grammarly, we build our models with safety and fairness as a priority, from how we sample and label data to how we train models, design prompts for large language models, and post-process AI output.”
Not publicly evidencedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“We do not allow our third-party service providers to train their models on user content.”
Customer data15% of the score74
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
“You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone. To do so, turn off Product Improvement and Training in your account settings.”
Vendor publishedGrammarly Docs | All-in-one AI Document Editor ↗retrieved Oct 5, 2026
“All users have the ability to opt out of allowing Grammarly to use their content to improve its products or train its models . We do not train on any content from certain business users or users whose accounts originate in the EU or UK, automatically.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Develop and improve AI. We also use information we collect to train our AI models. You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“One of the most important pillars of responsible AI is upholding privacy and security to protect all users, customers, and their companies’ reputations. We do not allow our third-party service providers to train their models on user content.”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly hosts data in Amazon Web Services data centers in the US East region and ensures continual product availability by using native backup tools. An industry-leading infrastructure provider, AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report.”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly encrypts all data in transit and at rest. Data transfer is protected using the industry-standard TLS 1.2 protocol, while data at rest in AWS is encrypted using AES-256 server-side encryption. Grammarly uses AWS Key Management Services for database encryption and secure key management. Enterprise clients can either provide their own encryption keys or use a Grammarly-managed key to control and view access to data stored at rest in Grammarly’s service.”
“Please note that if you save a document in the Grammarly Editor, we’ll store it until you delete the document or your Grammarly account.”
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“We retain personal data for as long as necessary to provide our products to you, to complete the transactions you have requested, to comply with our legal obligations, to resolve disputes, and for other legitimate business purposes. We retain the data we collect for different periods of time depending on what it is, how it’s used, and how you configure your settings.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“(i). Operating, providing, improving, troubleshooting, and debugging our Services (for example, your acceptance or rejection of our grammatical suggestions may help train our suggestion engine);”

Capped at 74: the evidence here is the vendor’s own account, with nothing independently corroborating it.

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“Trusted service providers. We use trusted service providers to help power our products and operate our business. They help with things like payment processing, AI technology, and cloud storage. These trusted service providers are bound by agreements that require them to follow data privacy and security requirements and to follow our instructions. For example, we restrict our AI service providers from training their models on user content of Superhuman customers.”
Vendor publishedResponsible AI | Grammarly ↗retrieved Oct 5, 2026
“In addition, we maintain a thorough vendor review process, repeated regularly, to conduct due diligence before engaging with any processors and subprocessors.”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly hosts data in Amazon Web Services data centers in the US East region and ensures continual product availability by using native backup tools. An industry-leading infrastructure provider, AWS is certified as compliant with ISO 27001 and has received a SOC 2 (Type 2) report.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“You acknowledge that the Third-Party Service might access or use your User Content, and you permit us to transmit your User Content to the provider of the Third-Party Service as necessary for the Third-Party Service to interoperate with our Services.”
Security foundation15% of the score65
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“Grammarly’s ongoing HackerOne bug bounty program promotes transparency and provides a channel for external security researchers to identify potential security concerns. Our team responds rapidly—and resolves these issues before they can be exploited. If you believe you’ve discovered a security-related issue, please report it at HackerOne or contact us at [email protected].”
Vendor publishedSecurity at Grammarly ↗retrieved Oct 5, 2026
“That’s why we undergo third-party network penetration tests as well as AWS security and corporate infrastructure security assessments and audits.”
Independent assurance evidence10% of the score55
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
“SOC 2 (Type 2) Grammarly’s SOC 2 (Type 2) report validates our controls based on the security, privacy, availability, and confidentiality trust services criteria. Contact us to read our report.”
“ISO/IEC 27001:2022 Grammarly’s information security management system meets the requirements of ISO 27001 and 27002 international standards. Read our certificate. ISO/IEC 27018:2019 Grammarly meets the requirements of ISO 27018 regarding our protection of personally identifiable information (PII) in the cloud. Read our certificate. ISO/IEC 42001:2023 Grammarly meets the requirements of ISO 42001 ensuring responsible AI development and use.”
“SOC 3 Grammarly’s SOC 3 report describes our validated controls regarding security, privacy, availability, and confidentiality. Read our public report. ISO/IEC 27017:2015 Grammarly’s information security practices meet the requirements of ISO 27017 regarding our provision and use of cloud services. Read our certificate. ISO/IEC 27701:2019 Grammarly's privacy information management system meets the requirements of ISO 27701 international standards.”
“Our certifications are based on comprehensive examinations conducted by independent third-party audit firms each year. You can rely on our certifications if you need them for any vendor risk-management purposes.”
Vendor publishedHow We Protect Your Privacy | Grammarly ↗retrieved Oct 5, 2026
“For transfers to the US, we are certified under the EU-US Data Privacy Framework, the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework regarding the collection, use and retention of personal data from the EU, UK and Switzerland (please see Grammarly on the list of DPF-certified companies ).”
Vendor publishedHow We Protect Your Privacy | Grammarly ↗retrieved Oct 5, 2026
“Yes, Grammarly is HIPAA-compliant. Please note that as per our Acceptable Use Policy , you should not store, transmit, or otherwise process any information via our services that falls within the definition of “Protected Health Information” under the HIPAA Privacy Rule (45 C.F.R. Section 164.051), unless you have entered into a current Business Associate Agreement with Grammarly.”
Registry verifiedCSA STAR Registry record — CSA STAR Level 2 ↗retrieved Oct 5, 2026

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score40
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedPrivacy Policy | Superhuman ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to content you upload to or output from our products using such accounts. Instead, we process such content on behalf of and in accordance with the contract and data protection terms with that Organization.”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“These Terms do not apply to our various enterprise-tier products and services, which are provided as subscriptions through our enterprise sales team to organizations (collectively, the “Enterprise-Tier Services”). If your organization has purchased the Enterprise-Tier Services, the governing terms and conditions will be our Customer Business Agreement .”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“SUPERHUMAN AND THE SUPERHUMAN ENTITIES DO NOT MAKE ANY REPRESENTATION OR WARRANTY REGARDING THE OUTPUTS THAT MAY BE GENERATED FROM USE OF GENERATIVE AI FEATURES, INCLUDING WITH RESPECT TO THE FACTUAL ACCURACY OF ANY OUTPUTS OR SUITABILITY FOR YOUR USE-CASE. ALL OUTPUTS ARE PROVIDED “AS IS” AND WITH “ALL FAULTS.””
Vendor publishedAcceptable Use Policy | Grammarly ↗retrieved Oct 5, 2026
“Automated Decisions. Do not use the services to make automated decisions with legal or similarly significant effects, including in any domains that may affect an individual’s rights, safety, health or well-being (for example, in the domains of finance, credit, insurance, employment, housing, education, essential services, healthcare, law or law enforcement, migration, management of critical infrastructure, judicial proceedings or social scoring).”
Vendor publishedTerms of Service | Grammarly ↗retrieved Oct 5, 2026
“If you open an Account on behalf of an Entity, we will process your personal information and that of the end users of that Account in accordance with our Data Privacy Addendum, and we and you agree to comply with its terms, as applicable.”

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 65 → 85
+2Have Customer data treatment disclosures independently corroboratedData 74 → 90
+2Have Governance & accountability disclosures independently corroboratedOrganisation 65 → 80
+2Complete the Legal & contractual transparency disclosureLegal Contractual 40 → 60
+2Complete the Model provider transparency disclosureModel 40 → 60

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 56 → up to 79 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESINFRASTRUCTURESuperhuman Platform Inc. (formerly Grammarly, Inc.)Superhuman Platform Inc. …GrammarlyGrammarlyGoGoDocsDocsAmazon Web Services (US East region)Amazon Web Services (US E…
View as list
Superhuman Platform Inc. (formerly Grammarly, Inc.) Uses Infrastructure Amazon Web Services (US East region)

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 10 — registry checks and verification ladders, click to view
SOC 2 Type 2Vendor claimed only

Security, privacy, availability and confidentiality trust services criteria; report available on request from sales.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SOC 3Vendor claimed only

Security, privacy, availability and confidentiality; described as a public report.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001:2022Claimed, scope unclear

ISMS certification claimed; certificate linked but issuer, certified scope and validity not stated on the page.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27017:2015Claimed, scope unclear

Cloud services controls claimed; issuer and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018:2019Claimed, scope unclear

PII protection in the cloud claimed; issuer and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27701:2019Claimed, scope unclear

Privacy information management system claimed; issuer and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001:2023Claimed, scope unclear

AI management system certification claimed for 'responsible AI development and use'; certified scope, issuer and validity not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-US Data Privacy Framework (with UK Extension and Swiss-US DPF)Vendor claimed only

Transfers of EU, UK and Swiss personal data to the US; registry-checkable at dataprivacyframework.gov but not verified in this scan.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

HIPAAVendor claimed only

Self-asserted compliance, not a third-party attestation; PHI may only be processed under a signed Business Associate Agreement.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Oct 5, 2026: Verified on the registry

Sources 13 — click to view
Artificial Intelligence (AI) at Grammarly
AI Documentation · Vendor · retrieved Oct 5, 2026
The Grammarly User Trust Center | Security, Privacy, & Compliance
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
How We Protect Your Privacy | Grammarly
Privacy Notice · Vendor · retrieved Oct 5, 2026
Security Compliances, Certifications, and Validations | Grammarly
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Grammarly for Google Docs | Grammarly
Product Documentation · Vendor · retrieved Oct 5, 2026
Acceptable Use Policy | Grammarly
Terms · Vendor · retrieved Oct 5, 2026
How to Cite a Newspaper Article in MLA
Technical Article · Vendor · retrieved Oct 5, 2026
Responsible AI | Grammarly
AI Documentation · Vendor · retrieved Oct 5, 2026
Security at Grammarly
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Privacy Policy | Superhuman
Privacy Notice · Vendor · retrieved Oct 5, 2026
Grammarly Docs | All-in-one AI Document Editor
Product Documentation · Vendor · retrieved Oct 5, 2026
Terms of Service | Grammarly
Terms · Vendor · retrieved Oct 5, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Grammarly at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.