Governing body
App Defense Alliance (ADA) & Google Trust & Safety
ADA CASA compliant
2–5 day turnaround
Find the right level of support for your assessment. Answer a few questions, see a tailored recommendation, and purchase your CASA AL1 Letter of Validation online when you're ready.
About 30 seconds · Instant pricing · No sales call required
Did Google notify your team that your app requires an annual CASA verification for sensitive or restricted OAuth scopes? Secusy validates your authenticated Burp or OWASP ZAP scans, helps resolve high-likelihood CWE failures, and issues your compliant LoV.
The definition
App Defense Alliance (ADA) & Google Trust & Safety
Burp Suite Professional & OWASP ZAP (authenticated)
Official signed Letter of Validation (LoV)
2 to 5 days (tier dependent)
Plan your assessment
Tell us when you need Google's Letter of Validation and how much help you want. We'll suggest a plan, explain why it fits, and show the price of every option.
CASA plan finder
Your recommendation and all prices appear at the end.
About 30 seconds
Choose the closest window. If you know the exact date, you can add it below.
Before validation
CASA AL1 accepts specific authenticated scan artifacts and scope boundaries. Meet these criteria before your Letter of Validation can be processed.
After checkout
Payment isn't a black hole — here's the exact fulfillment pipeline from purchase to signed LoV.
Submit your Google Cloud project number, target app URL, and test account credentials via the Secusy customer portal.
Start filling out the SAQ, providing required responses and evidence.
Run our integrated scanner, or provide your ZAP or Burp authenticated scan results mapped against the ADA CASA requirements.
A certified security engineer verifies the scan outputs and SAQ responses, helps dispute false positives, and provides remediation guidance to resolve genuine blockers.
LoV is submitted to Google's security team for approval. Download your signed, timestamped Letter of Validation from the portal once issued.
Web apps, browser extensions, and SaaS tools requesting Google OAuth sensitive scopes —e.g. Google Drive metadata, Google Calendar, or Contacts — fall under this requirement.
The mandatory baseline covering OWASP ASVS Level 1 controls. Validated via SAST, DAST, and configuration questionnaires — no weeks of manual ethical hacking required.
Required for restricted scopes — e.g. full Gmail read/write access via mail.google.com — requiring certified lab manual penetration testing.
Explore CASA AL2Questions