// Trust & Security Report
Rows
Rows is an AI-powered spreadsheet / data-analyst tool (core product), with a browser extension (RowsX) for extracting web data into spreadsheets and a public API. Rows was acquired by Superhuman (formerly Grammarly) in February 2026; per the vendor's announcement, the standalone product was scheduled to be sunset by May 31, 2026, with its capabilities folded into Superhuman's Coda product. As of July 2026, rows.com is still live and displays a banner confirming the acquisition.
Certifications held
2
Maturity
Growth
Trains on your data
No
Trust center
No
// Certification ledger
Each held certification is backed by a verbatim quote from the vendor's own trust or security page. “Not confirmed” means we could not verify it publicly, not that the vendor lacks it.
Verify on rows.com“SOC 2 Type II Certified: This certification confirms that Rows meets strict criteria for security, availability, and confidentiality”
Verify on rows.com“We ensure that personal data is processed in accordance with the General Data Protection Regulation (GDPR)... If you need a Data Processing Agreement with us, please find the already signed version here”
> Show 6 unconfirmed / not-held certifications
source: rows.comNo public evidence found. Rows' own security and privacy pages (rows.com/docs/how-do-you-manage-security, rows.com/privacy) do not mention ISO 27001. A third-party summary claims 'ISO 27001 Compliant,' but this is not corroborated on any rows.com page.
source: rows.comNo public evidence found. HIPAA is not mentioned anywhere on rows.com's security or privacy pages; Rows is a general business spreadsheet/data tool with no stated healthcare/BAA offering.
source: rows.comPCI DSS is referenced only in connection with Rows' payment processor (Stripe), not Rows' own systems: payment providers 'comply with Payment Card Industry (PCI) Data Security Standards' and are 'certified by an independent PCI Qualified Security Assessor.' This is the payment processor's certification, not Rows'.
source: rows.comNo public evidence found on any rows.com page. A third-party aggregator claims FedRAMP compliance, but this has no vendor-domain support.
source: rows.comNo public evidence found. Rows describes AI-training posture in its privacy policy but makes no claim of a formal AI-governance certification.
// Privacy & AI training
Trains on customer data
No
Data processing agreement
Offered
Data region
EU/EEA. Privacy policy states servers are 'geographically located in the European Union (EU) or the European Economic Area (EEA)'; the security page states 'All data is stored in European data centers, encrypted at rest and in transit.' Hosting infrastructure includes Google Cloud Platform and AWS.
Vendor states data shared with the Rows AI Analyst is 'not used for training purposes.' The privacy policy specifies the AI feature uses OpenAI and Groq as sub-processors; OpenAI may retain data 'for up to 30 days' for abuse monitoring while 'Groq does not retain your data after processing.' Rows also states elsewhere: 'Rows does not access your spreadsheets, and you can delete your data anytime.' Following the acquisition, Rows' privacy policy states Superhuman's Privacy Policy and Terms apply as of June 16, 2026 (already in effect), so the AI-training posture described here may be superseded by Superhuman's policy going forward.
// Security controls
Encryption in transit
HTTPS/TLS protocols when sending data from spreadsheet to Rows servers
rows.comData residency
European data centers (EU/EEA); infrastructure on Google Cloud Platform and AWS
rows.comVulnerability disclosure
Security researchers can report issues to security@rows.com with proof-of-concept and CVSS scoring; submissions can be encrypted with Rows' published PGP key
rows.comAI data handling
User data shared with the AI Analyst feature is not used to train AI models; sub-processors are OpenAI (up to 30-day retention) and Groq (no retention after processing)
rows.com// Products & data scope
Data it handles: Business data imported from 50+ integrations (social media, ad platforms, data warehouses, back-office tools) and from uploaded documents/PDFs; processed in a hosted spreadsheet.
Marketed as 'Your new AI Data Analyst'; extracts data from PDFs, imports business data, and answers questions in plain language.
Data it handles: Spreadsheet data sent to OpenAI/Groq for query answering; vendor states this data is not used for model training.
Sub-feature of the core product, described on rows.com/ai.
Data it handles: Extracts tables from third-party websites into a Rows spreadsheet.
One-click import of web page tables; separate from the core AI Analyst.
Data it handles: Programmatic read/write access to a user's Rows spreadsheets and data.
Referenced in the site footer as 'API Docs.'
// What to watch
- Rows was acquired by Superhuman (formerly Grammarly), announced February 22, 2026. The vendor's blog post stated the standalone Rows product would be gradually sunset over three months, with full shutdown by May 31, 2026. As of July 2026, that date has passed, yet rows.com remains live with a banner ('Rows joined Superhuman') rather than a hard redirect, so the product's continued independent availability is uncertain.
- Rows' privacy policy states that the Superhuman Privacy Policy and Terms apply as of June 16, 2026, a date already in effect. The AI-training and data-handling posture described here, sourced from Rows' legacy privacy policy, may already be superseded by Superhuman's policy.
- A third-party summary claims Rows is PCI Compliant, HIPAA Compliant, SOC 2 Compliant, GDPR Compliant, ISO 27001 Compliant, FedRAMP Compliant, and CSA STAR Level 1 Compliant. Beyond SOC 2 Type II and a GDPR posture, none of these claims are corroborated on rows.com.
- PCI DSS language on rows.com/privacy refers to the payment processor's (Stripe's) certification, not Rows' own infrastructure.
- No dedicated trust center (e.g. a Vanta/Drata/SafeBase-hosted trust portal) exists; the only vendor-domain security disclosure is a single docs article (rows.com/docs/how-do-you-manage-security).
// At a glance
Pricing model
Freemium / subscription tiers (Free, paid team/business tiers referenced on rows.com/pricing); tier-by-tier feature and compliance differences were not itemized in the available vendor pages.
Self-hostable
No
// How we verified this
Every certification marked HELD is confirmed against a verbatim quote on Rows GmbH's own trust, security, or privacy pages. We reject certifications claimed only on third-party aggregators, on a cloud host's behalf, or by a similarly named company.
Last verified 2026-07-09. Compliance changes over time. Always confirm directly with the vendor before relying on any certification for a purchasing or compliance decision.
rows.com