Grammarly security review: SOC 2, AI training & subprocessors

What Grammarly publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.

Transparency score
75/100
SOC 2
SOC 2 Type II
ISO 27001
Claimed
Trains AI on your data?
See quotes
Subprocessors
Not found
DPA
Not found

"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.

Does Grammarly train AI on your data?

Statements differ between pages

Grammarly's own words (grammarly.com/ai/responsible-ai):

We do not allow our third-party service providers to train their models on user content.

Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.

Other statements we found
You can opt out of allowing Grammarly to use your content to train its models and improve its product for everyone.
grammarly.com/trust
You can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings.
superhuman.com/legal/privacy-policy
We do not allow our third-party service providers to train their models on user content.
grammarly.com/ai/responsible-ai

Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.

Certifications Grammarly claims

Certification or reportMentioned on
SOC 2 Type IIgrammarly.com/compliance
SOC 3grammarly.com/compliance
ISO/IEC 27001grammarly.com/compliance
ISO/IEC 27017grammarly.com/compliance
ISO/IEC 27018grammarly.com/compliance
ISO/IEC 27701grammarly.com/compliance
ISO/IEC 42001grammarly.com/compliance
HIPAAgrammarly.com/compliance

Privacy laws and frameworks mentioned: GDPR, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.

A certification on a website is a claim. For anything sensitive, ask Grammarly for the SOC 2 report or ISO certificate.

Grammarly subprocessors

Our reader didn't find a subprocessor list on Grammarly's public pages. It may be published somewhere we couldn't reach, such as a trust portal that needs JavaScript or a login. Ask Grammarly for it if you need it.

Security features mentioned

SSO / SAMLMentioned
SCIM provisioningNot found
Multi-factor authenticationMentioned
Encryption at restNot found
Encryption in transitNot found
Penetration testingMentioned
Bug bounty / disclosure programMentioned
Audit logsNot found
Data residencyNot found
security.txt contactsecurity@grammarly.com

Key documents

Trust / security centergrammarly.com/trust
Privacy policygrammarly.com/privacy-policy
Subprocessor listNot found
Data processing agreement (DPA)Not found
AI policygrammarly.com/ai/responsible-ai
Termsgrammarly.com/terms
Status pagestatus.grammarly.com

How this score is worked out

CheckPointsResult
Security or trust page15Yes
Certifications listed20Yes
Privacy policy10Yes
Subprocessor list15No
DPA available10No
AI training policy stated15Yes
security.txt contact5Yes
Status page10Yes

The score measures how much of a standard security review our reader could answer from Grammarly's public pages. It is not a rating of how secure Grammarly is, and a "No" can mean the document exists where our reader couldn't see it.

Check another vendor

Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.

Other Productivity vendors

Airtable · Asana · Atlassian · Basecamp · Box · Calendly · ClickUp · Coda · DocuSign · Dropbox · Evernote · Figma

Source: Grammarly's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Grammarly. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.