All engagements conducted under NDA·Evidence preserved to technical chain-of-custody standards·Engagements limited to qualified organizations

Free scanThe studyForensic TriageForensic AuditAI VendorsResearch
Free scan · no install

Does Grammarly have a HIPAA BAA — and why is your contract now with Superhuman?

Free & Pro: No BAA, HIPAA is Enterprise-only · Training control exists, default not published · Retention not stated

Enterprise (via Superhuman Go): BAA available, Enterprise only · Training off by default · The Mail agent is not covered by the BAA

The legal entity is now Superhuman Platform Inc. (formerly Grammarly); grammarly.com legal pages redirect to superhuman.com.

Free & ProEnterprise (via Superhuman Go)
HIPAA BAANothe HIPAA-compliant offering "is exclusively available to customers with a Superhuman Enterprise plan"YesEnterprise only - requires an Enterprise-level Go plan, a signed BAA, and SAML SSO. The Mail agent is explicitly not covered by the BAA, and third-party agents have no BAA protection
Trains on your dataControl existsdefault not published - users "can decide whether Superhuman can use your user content to train our AI models by adjusting the available training control(s) in your account settings"; no default state is stated for these tiers, unlike Enterprise where it is off by defaultNo"Product Improvement and Training is off by default" for Enterprise customers
Survives deletionNot publicly stated"We retain the data we collect for different periods of time depending on what it is, how it's used, and how you configure your settings," with no timeframes and no explicit statement on account deletionOn termination, "stored data is deleted in accordance with Superhuman's data retention policies"; no retention period stated. Default session timeout is 30 days, customizable
Deployer / admin log accessNot publicly stated for these tiersaudit logs are an Enterprise feature, available on requestYesaudit logs available upon request
Third-party attestationSOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27701 and 42001:2023. Scope is not stated per product or planSOC 2 Type 2, SOC 3, ISO/IEC 27001:2022, 27017, 27018, 27701 and 42001:2023. Scope is not stated per product or plan
Commonly mistaken for — Free & Pro

Enterprise, the only tier with a BAA. Also the corporate rename - the entity is now Superhuman Platform Inc. (formerly Grammarly) and grammarly.com legal pages redirect to superhuman.com. The former Business tier no longer appears in the plan list

Commonly mistaken for — Enterprise (via Superhuman Go)

The assumption that a signed BAA covers the whole product - the Mail agent sits outside it. Also that the vendor is still contracting as Grammarly, Inc.

Source: https://support.grammarly.com/hc/en-us/articles/45483890812557-Superhuman-Go-HIPAA-Compliance-InformationDocument: Grammarly Support - Superhuman Go HIPAA Compliance InformationVerified: September 2, 2026Verified by: Adil — Shadow AI Forensics

Vendor terms change without notice. This page reflects what Grammarly published as of September 2, 2026. Re-verified quarterly.

This page states what the vendor published. It does not score them.

If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.

See how AVRA works →

Want all 13 tools in one file?

AI Vendor Compliance Quick-Reference

Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.