90 Days Gen AI Risk Trial -Start Now
Book a demo
Writing·Free; Pro $12/mo; Enterprise custom (100-seat minimum for BAA)·grammarly.com

Grammarly

Grammarly is an AI writing assistant for grammar, tone, clarity, and generative drafting that runs across browsers, desktop apps, and mobile keyboards.

Risk Score
Medium
5/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Grammarly is a widely deployed AI writing assistant offering grammar, spelling, clarity, tone, and style suggestions alongside generative drafting and rewriting features. It runs as browser extension, desktop app, mobile keyboard, and embedded SDK. Grammarly is SOC 2 compliant and holds ISO 27001 and related certifications. The Business Enterprise tier (minimum 100 seats) supports HIPAA BAAs, BYOK encryption, DLP, and custom roles. By default, Grammarly may use content to improve its models unless users opt out in settings.

Risk factors

3
  • Processes user text data which may include sensitive information
  • Cloud-based with potential data sharing
  • No clear opt-out for training on user data

Recommendations

8
  • Move all staff to managed Grammarly Business or Enterprise; block personal accounts via SSO
  • Toggle off Product Improvement and Training in account or org settings
  • For healthcare use, require the Business Enterprise plan with executed BAA (100+ seats)
  • Enable DLP and BYOK on Enterprise to reduce vendor-side exposure
  • Review browser-extension install policy via endpoint management
  • Exclude Grammarly from fields handling passwords, PHI, or payment data via domain allowlist
  • Audit SOC 2 and ISO reports during annual vendor review
  • Train users to disable Grammarly in sensitive workflows (legal, HR, finance)

Data handling

Storage
AWS-hosted US infrastructure with TLS in transit and AES-256 at rest; global CDN for browser extension assets.
Retention
Documents in Grammarly Editor retained until user deletes document or account. Opt-out of tailored assistance triggers deletion of personalization data.
Training on inputs
By default Grammarly may use user content to train and improve models; users can opt out via Product Improvement and Training setting.