Superhuman × Cloudflare
Talk to Cloudflare →
Executive Brief · Zero Trust & AI Expansion

One Cloudflare perimeter for every brand, seat & AI agent Superhuman ships.

Cloudflare already sits in front of superhuman.com and secures 1,770 Zero Trust seats today*. As Grammarly, Coda (now Superhuman Docs) and Superhuman Mail finish merging into one company, the fastest path to covering every new seat — and every new MCP connector — is the network already running underneath you.

Why now

Grammarly — founded in 2009 — spent 2025 acquiring Coda (relaunched as Superhuman Docs) and the original Superhuman Mail app, then unified all three products under one new brand: Superhuman (per superhuman.com/about, accessed Oct 2026). The combined suite now reports 40M+ daily active users, 50K+ organizations, and 200B+ words analyzed daily — the same source lists OpenAI, Figma, HubSpot, DoorDash, Expensify and Geico among its customers.

Those are security-conscious enterprise buyers who will scrutinize how Superhuman governs its own data and AI usage. And the product itself has moved from "user of AI" to "AI infrastructure provider": superhuman.com's own navigation now advertises public Mail MCP and Docs MCP connectors plus an Agent Store of third-party agents — a live, public MCP attack surface that didn't exist at this scale a year ago.

From three companies to one Zero Trust perimeter

Grammarly, Coda (Superhuman Docs) and Superhuman Mail merged into one brand in 2025. Each came with its own workforce and identity footprint — all converging on the Cloudflare One tenant already covering 1,770 seats*.
3 merged orgs → 1 Zero Trust perimeter
Grammarlyoriginal org · 2009
Coda→ Superhuman Docs · 2025
Superhuman Mailindependent co. · 2025
Okta (shared tenant)sso.superhuman.com*
WorkOSenterprise SSO · auth.superhuman.com*
Google Workspacecorp mail · MX records*
Cloudflare One 1,770 seats today* · one policy engine
Goal: cover 100% of the combined headcount

Seven plays: seat growth, the modules already on the table, and the new AI ask

Mapped to the live conversation — the 1,770-seat base, the DLP/CASB/RBI interest already on record, and the new AI Gateway / MCP Protection / Shadow AI ask.
01

Zero Trust seat growth — fold in the acquisitions

Growth driver · M&A integration

Coda and the original Superhuman Mail each brought their own workforce before 2025. As those teams land on the shared Okta tenant and WorkOS-based SSO, every newly merged employee is a candidate for the existing Cloudflare One agreement — the single largest untapped seat pool on the account.

  • Today: 1,770 Zero Trust seats *per account-team
  • Shared Okta tenant already live: grammarly.customdomains.okta.com
  • WorkOS (auth.superhuman.com) handles enterprise SSO/directory sync — a natural Access on-ramp
  • Combined Coda + Mail headcount to be sized with the account team
02

CASB — one SaaS inventory across three merged orgs

↳ reopens the CASB conversation

Three previously independent companies bring three independent sets of sanctioned — and unsanctioned — SaaS apps. API-based CASB wired into the now-shared Okta and Google Workspace tenant gives IT one inventory instead of reconciling three shadow-IT pictures by hand.

  • Google Workspace is system-of-record for corporate mail (MX → aspmx.l.google.com)
  • Shared Okta tenant is the single wiring point for CASB API connectors
  • Surfaces OAuth-connected apps inherited from Coda and the original Mail org
  • Closes the CASB interest already flagged by the account
03

DLP — protect what 200B+ words a day actually contain

↳ reopens the DLP conversation

Per superhuman.com/about, the combined suite analyzes 200B+ words daily across Mail, Docs and AI assistants — customer email, contracts and internal docs, now flowing through AI prompts and third-party agents too. Cloudflare DLP ships in the same Zero Trust bundle as the existing 1,770 seats, extending one policy engine to catch sensitive data before it leaves the SaaS boundary.

  • 200B+ words/day analyzed across the suite (superhuman.com/about)
  • DLP ships in the same SKU as the existing seats — no new endpoint agent
  • Pairs with CASB (play 2) for API-level + inline inspection
  • Matches the DLP interest already on record
04

Remote Browser Isolation — isolate the risky edges

↳ reopens the RBI conversation

An AI company building agents and connectors needs engineers and support staff to research the open web freely — competitor tools, AI-detection services like gptzero.me (already loaded on superhuman.com), unknown integrations — without exposing managed devices directly. RBI rides the same WARP client already deployed on 1,770 endpoints.

  • No new endpoint agent — rides the existing WARP client
  • Fits the contractor / BYOD access scenarios already discussed
  • Isolates research into competitor and AI-tooling sites
  • Closes the RBI interest already on record
05

AI Gateway — govern every LLM call the company makes

New interest · cost, cache & audit for AI

Superhuman's own homepage calls itself "the AI productivity suite" and lists OpenAI among its trusted-by customers. Between Superhuman Go, Grammarly's generative features and Docs AI, there are almost certainly more first-party and internal LLM integrations than one team can track by hand. AI Gateway puts a single logged, rate-limited, cache-enabled front door on every model call, any provider, without touching application code.

  • Homepage positioning: "AI productivity suite" (superhuman.com)
  • One audit trail across every internal + product LLM call
  • Cache + rate-limit to control token spend as usage scales past 40M+ DAU
  • Foundation the MCP Protection play below builds on
06

MCP Protection — govern the MCP servers you already publish

New interest · a live public attack surface

superhuman.com's own navigation lists "Connectors → Mail MCP, Docs MCP" and an "Agent Store" of third-party agents that connect to customer mail and docs. That's a live, public MCP surface today, not a hypothetical. Cloudflare Access can front those MCP servers with authenticated, logged entry, and AI Gateway can apply rate limits and audit to every inbound agent call — so Agent Store integrations only ever get the access they're scoped for.

  • Identified: superhuman.com nav — "Mail MCP", "Docs MCP", "Agent Store"
  • Access-fronted MCP servers: every agent call authenticated & logged
  • Pairs with AI Gateway for inbound-agent rate limits & audit
  • Directly protects the product surface the account flagged as new interest
07

Shadow AI visibility — find what 40M+ users actually use

New interest · discover ungoverned AI tools

Superhuman's own trusted-by list includes OpenAI, Figma, HubSpot, DoorDash, Expensify and Geico — sophisticated, security-conscious customers who will ask how Superhuman governs its own AI tool usage. Gateway and CASB logs across the 1,770 managed endpoints surface every AI SaaS app employees actually open, sanctioned or not, turning a stated interest into a running inventory IT can act on.

  • Trusted-by logos: OpenAI, Figma, HubSpot, DoorDash, Expensify, Geico (homepage)
  • Built on the same Gateway logs already flowing from 1,770 seats
  • Feeds policy decisions for CASB (sanction) and DLP (restrict) above
  • A concrete 30-day discovery exercise, not a new agent rollout

Expansion roadmap

Sequenced around the live conversation — integrate the acquisitions first, then close the modules already discussed, then make AI governance the default.
Next 2 quarters

Integrate the acquisitions

  • Migrate Coda/Docs + original Mail-team identities onto the shared Okta/WorkOS tenant → Access
  • Size combined headcount; scope seat growth beyond the 1,770 baseline
  • Stand up AI Gateway logging (read-only discovery) on top internal + product LLM calls
  • Kick off a Shadow AI discovery pass across the existing 1,770 endpoints
By ~12 months

Close the open modules

  • Turn on DLP policies tuned to Mail/Docs content and AI prompts
  • Enable CASB API connectors across the shared Okta/Google Workspace tenant
  • Pilot RBI for contractor access and high-risk browsing categories
  • Put Access in front of Mail MCP / Docs MCP; scope Agent Store calls
Within 18–24 months

AI governance, company-wide

  • DLP + CASB + RBI live across 100% of combined headcount — not just 1,770 seats
  • AI Gateway + MCP Protection as the default front door for every current & future agent/connector
  • Single Zero Trust + AI security renewal spanning Grammarly, Docs and Mail
  • Unified audit trail ready for enterprise customers' own security reviews of Superhuman

IT & security snapshot

Technical facts are evidence-based; seat counts and interest areas are account-team input, marked accordingly.
FunctionTodayHow it was identifiedCloudflare path
Zero Trust / SSE seats 1,770 seats account-team Account-team input Expand to combined headcount (Docs + Mail + Grammarly)
Identity / SSO Shared Okta tenant + WorkOS identified sso.superhuman.com → grammarly.customdomains.okta.com; auth.superhuman.com → workos-dns.com Cloudflare Access (SSO + device posture)
DNS / edge Cloudflare identified Nameservers ada/noah.ns.cloudflare.com; cf-ray on root response Already consolidated — foundation for every play below
Secondary CDN layer AWS CloudFront identified via: cloudfront.net on root response Informational — no action required
Corporate mail Google Workspace identified MX → aspmx.l.google.com CASB API-connector target
Data Loss Prevention Not yet enabled account-team Past interest, per account-team Cloudflare DLP
CASB Not yet enabled account-team Past interest, per account-team Cloudflare CASB
Remote Browser Isolation Not yet enabled account-team Past interest, per account-team Cloudflare RBI
AI / LLM traffic Ungoverned, direct calls "AI productivity suite" positioning + OpenAI trusted-by logo (homepage) AI Gateway
MCP surface Public Mail MCP + Docs MCP + Agent Store identified superhuman.com nav: Connectors → Mail MCP, Docs MCP; Agent Store MCP Protection (Access + AI Gateway)

How we know — observed on superhuman.com

Technical facts below were identified from public DNS, HTTP headers, and the live superhuman.com site and navigation. Account-specific figures are marked as account-team input.
Cloudflare DNS + edge already in front of superhuman.com Okta (shared w/ Grammarly) sso.superhuman.com WorkOS auth.superhuman.com Google Workspace MX records AWS CloudFront via header Zendesk help.superhuman.com Ghost blog.superhuman.com SendGrid email.superhuman.com Mail MCP / Docs MCP / Agent Store superhuman.com nav 1,770 Zero Trust seats *per account-team Past DLP / CASB / RBI interest *per account-team New AI Gateway / MCP / Shadow AI interest *per account-team
LIVE Checking the Cloudflare edge serving this page…