
A well-governed AI email suite, and the questions that open the moment employees start connecting agents to it.
The rating: Low Risk, and earned. SOC 2 Type 2, the ISO 27001 family, opt-in AI, zero data retention with the model provider, no training on customer data.
Exposure Landscape: not in the product. In the agents and integrations employees connect to it, the plan tier each account runs under, and the data-use settings no one on the security side has reviewed.
Why it matters: a rating is a snapshot. The live tool changes the moment someone connects an agent.
A risk rating is an attestation about a point in time and a specific contract. It says far less about the tool your employees are actually running.
Superhuman is a useful case in that gap. It is a well-run product with a strong compliance posture, and Singulr Pulse™ rates it Low Risk.
The reason it still earns a Risk Spotlight is directional. The product is moving toward agents and third-party integrations, and that is precisely where a clean rating stops describing the live environment.
Superhuman began as an AI email client that drafts in your voice, triages the inbox, and answers questions across mail, calendar, and the web. Adoption tends to run ahead of review, because the people who live in email install it on their own.
It is no longer a single app. Superhuman now sits inside a four-product suite with Grammarly, Docs, and the Superhuman Go assistant, a marketplace of third-party agents, and connectivity into more than 100 applications.
That changes the governance question. An email client and an assistant that can reach into a hundred connected systems on a user's behalf are not the same risk object, even when they share a brand and a rating.

We read Superhuman's live Privacy Policy, Terms of Service, and Trust Center rather than the marketing pages. On the fundamentals, the posture is strong.
The certification set is broad and current: SOC 2 Type 2, ISO/IEC 27001, 27017, 27018, and 27701, GDPR, and CCPA. Data transfers are covered through the EU-U.S., UK, and Swiss Data Privacy Framework and standard contractual clauses.
The operational signals a review looks for are present too. There is a published DPA, a named Data Protection Officer, cyber insurance, an "A" from SecurityScorecard, encryption at rest and in transit, and access and logging controls.
The stance on AI is stronger than most of the category. Superhuman AI is opt-in, and the company states it does not and will not permit its AI providers to train on customer data.
Superhuman runs its AI features on OpenAI's API under a zero data retention (ZDR) arrangement, which OpenAI itself confirms as well with “your text is processed to generate a response and not retained by the model provider afterward.” User content is never sold, which is a genuine differentiator in a market where training on customer content by default is common.
Ownership favors the customer. Under the Terms, you retain all rights to your content, and Superhuman takes only the operational license it needs to run the service.
Enterprise agreements go further, adding IP indemnification for AI outputs. None of this is boilerplate, the rating is fair.
A rating describes the vendor's posture. It says nothing about the configuration an individual employee has enabled inside the account they use each day.
With Superhuman, that gap concentrates in three places, and each of them sits outside what a one-time assessment captures.
Superhuman's Terms are explicit: when a user connects a third-party service or a marketplace agent, they authorize Superhuman to transmit their content to that provider. From there, the provider's own terms govern, and the Privacy Policy states that Superhuman neither owns nor controls those offerings.
In practice, this introduces a fourth party into your data flow with no TPRM review, DPA, or sub-processor notification. Every agent an employee installs is a new outbound path, authorized at the edge by someone who is not accountable for the program.
This is also the fastest-growing part of the product. Superhuman Go reaches across more than 100 apps and an Agent Store of third-party agents, so the surface expands with each integration a user turns on.
The training commitment is narrower than it first reads. Superhuman states that model training is off by default, but only for its Business and Education plans, it doesn’t address its other plans.
That distinction maps directly onto how these tools spread. The enterprise agreement, with its DPA, indemnification, and default protections, governs only the accounts under that contract.
Self-serve and free sign-ups fall under consumer terms, which are exactly the terms the default commitment does not speak to. The sanctioned deployment and an employee's personal account can be the same product with a materially different data posture.
The email product runs on a chain of subprocessors, including OpenAI, Google Cloud, and others handling vector storage, messaging, and data pipelines. That chain is a living list, which makes the case for a live picture, not a snapshot taken at onboarding.
Separately, and scoped carefully, the platform shares identifiers and inferences, not email content, with advertising and social networks. Under several US state laws, this can constitute a "sale" or a "share," subject to an opt-out that someone has to set.
Retention is defined as "as needed," without fixed durations. Against DSAR and deletion obligations, that is a gap to close in the contract rather than leave open.
Superhuman is a good tool, and a Low Risk rating on a vendor this well-certified is worth trusting. The exposure has nothing to do with a flawed product.
It accumulates at the edges, as capable and well-liked tools gain agentic reach and employees connect them to everything else they use. The terms that govern those connections are ones no one on the security side has reviewed.
The pattern is not specific to Superhuman. It is the shape of enterprise AI adoption now. A tool assessed as one thing becomes another. Agents act across systems on a user's behalf. Data-use settings vary by plan and by account, and no single sign-off covers all three.
A point-in-time review cannot keep pace with any of it.
Singulr Pulse™ is built for that reality. It keeps the live picture current across every AI service in your environment: the agents and third-party integrations connected to each tool, the data they can reach, the training and data-use settings on each account, and the moment an approved tool becomes an outbound path.
Governance stays tied to how a tool is actually configured and used, down to the account and the integration, and it updates as those change.
That is the difference between knowing a tool was safe and knowing it still is.
See how Singulr Pulse rates the AI tools already running in your environment: https://singulr.ai/request-a-demo
We Put You In Control Of AI.
Complete visibility across all three AI vectors in your environment, including agents and embedded SaaS AI
Singulr Pulse™ intelligence and the live risk signals that feed your control plane
Continuous red teaming, identifying control gaps and vulnerabilities in real time
Singulr Runtime Control™ enforcing governance intent without slowing innovation
