Cloudflare already sits in front of superhuman.com and secures 1,770 Zero Trust seats today*. As Grammarly, Coda (now Superhuman Docs) and Superhuman Mail finish merging into one company, the fastest path to covering every new seat — and every new MCP connector — is the network already running underneath you.
Grammarly — founded in 2009 — spent 2025 acquiring Coda (relaunched as Superhuman Docs) and the original Superhuman Mail app, then unified all three products under one new brand: Superhuman (per superhuman.com/about, accessed Oct 2026). The combined suite now reports 40M+ daily active users, 50K+ organizations, and 200B+ words analyzed daily — the same source lists OpenAI, Figma, HubSpot, DoorDash, Expensify and Geico among its customers.
Those are security-conscious enterprise buyers who will scrutinize how Superhuman governs its own data and AI usage. And the product itself has moved from "user of AI" to "AI infrastructure provider": superhuman.com's own navigation now advertises public Mail MCP and Docs MCP connectors plus an Agent Store of third-party agents — a live, public MCP attack surface that didn't exist at this scale a year ago.
Coda and the original Superhuman Mail each brought their own workforce before 2025. As those teams land on the shared Okta tenant and WorkOS-based SSO, every newly merged employee is a candidate for the existing Cloudflare One agreement — the single largest untapped seat pool on the account.
Three previously independent companies bring three independent sets of sanctioned — and unsanctioned — SaaS apps. API-based CASB wired into the now-shared Okta and Google Workspace tenant gives IT one inventory instead of reconciling three shadow-IT pictures by hand.
Per superhuman.com/about, the combined suite analyzes 200B+ words daily across Mail, Docs and AI assistants — customer email, contracts and internal docs, now flowing through AI prompts and third-party agents too. Cloudflare DLP ships in the same Zero Trust bundle as the existing 1,770 seats, extending one policy engine to catch sensitive data before it leaves the SaaS boundary.
An AI company building agents and connectors needs engineers and support staff to research the open web freely — competitor tools, AI-detection services like gptzero.me (already loaded on superhuman.com), unknown integrations — without exposing managed devices directly. RBI rides the same WARP client already deployed on 1,770 endpoints.
Superhuman's own homepage calls itself "the AI productivity suite" and lists OpenAI among its trusted-by customers. Between Superhuman Go, Grammarly's generative features and Docs AI, there are almost certainly more first-party and internal LLM integrations than one team can track by hand. AI Gateway puts a single logged, rate-limited, cache-enabled front door on every model call, any provider, without touching application code.
superhuman.com's own navigation lists "Connectors → Mail MCP, Docs MCP" and an "Agent Store" of third-party agents that connect to customer mail and docs. That's a live, public MCP surface today, not a hypothetical. Cloudflare Access can front those MCP servers with authenticated, logged entry, and AI Gateway can apply rate limits and audit to every inbound agent call — so Agent Store integrations only ever get the access they're scoped for.
Superhuman's own trusted-by list includes OpenAI, Figma, HubSpot, DoorDash, Expensify and Geico — sophisticated, security-conscious customers who will ask how Superhuman governs its own AI tool usage. Gateway and CASB logs across the 1,770 managed endpoints surface every AI SaaS app employees actually open, sanctioned or not, turning a stated interest into a running inventory IT can act on.
| Function | Today | How it was identified | Cloudflare path |
|---|---|---|---|
| Zero Trust / SSE seats | 1,770 seats account-team | Account-team input | Expand to combined headcount (Docs + Mail + Grammarly) |
| Identity / SSO | Shared Okta tenant + WorkOS identified | sso.superhuman.com → grammarly.customdomains.okta.com; auth.superhuman.com → workos-dns.com | Cloudflare Access (SSO + device posture) |
| DNS / edge | Cloudflare identified | Nameservers ada/noah.ns.cloudflare.com; cf-ray on root response | Already consolidated — foundation for every play below |
| Secondary CDN layer | AWS CloudFront identified | via: cloudfront.net on root response | Informational — no action required |
| Corporate mail | Google Workspace identified | MX → aspmx.l.google.com | CASB API-connector target |
| Data Loss Prevention | Not yet enabled account-team | Past interest, per account-team | Cloudflare DLP |
| CASB | Not yet enabled account-team | Past interest, per account-team | Cloudflare CASB |
| Remote Browser Isolation | Not yet enabled account-team | Past interest, per account-team | Cloudflare RBI |
| AI / LLM traffic | Ungoverned, direct calls | "AI productivity suite" positioning + OpenAI trusted-by logo (homepage) | AI Gateway |
| MCP surface | Public Mail MCP + Docs MCP + Agent Store identified | superhuman.com nav: Connectors → Mail MCP, Docs MCP; Agent Store | MCP Protection (Access + AI Gateway) |