ADA CASA compliant

2–5 day turnaround

Google CASA Tier 2 / AL1 Assessment & Letter of Validation (LoV)

Find the right level of support for your assessment. Answer a few questions, see a tailored recommendation, and purchase your CASA AL1 Letter of Validation online when you're ready.

About 30 seconds · Instant pricing · No sales call required

Backed byGoogle Approved CASA AL1 Testing Lab.
Testing LabValueMentor
AssessmentAL1 (formerly Tier 2) CASA Assessment
Governing bodyApp Defense Alliance (ADA) & Google Trust & Safety
Accepted scannersBurp Suite Professional & OWASP ZAP (authenticated)
DeliverableOfficial signed Letter of Validation (LoV)
Turnaround2 to 5 days (tier dependent)
Validity1 year (annual recertification required)

Did Google notify your team that your app requires an annual CASA verification for sensitive or restricted OAuth scopes? Secusy validates your authenticated Burp or OWASP ZAP scans, helps resolve high-likelihood CWE failures, and issues your compliant LoV.

The definition

What is Google CASA AL1?

Google CASA AL1 (App Defense Alliance CASA Assurance Level 1, also called Tier 2) is the annual security verification Google requires for apps requesting sensitive or restricted OAuth scopes. It's validated through an authenticated Burp Suite or OWASP ZAP scan plus a Self-Assessment Questionnaire, and results in a signed Letter of Validation (LoV) that Google Trust & Safety accepts as proof of compliance — no weeks-long manual penetration test required.
  • Governing body

    App Defense Alliance (ADA) & Google Trust & Safety

  • Accepted scanners

    Burp Suite Professional & OWASP ZAP (authenticated)

  • Deliverable

    Official signed Letter of Validation (LoV)

  • Turnaround

    2 to 5 days (tier dependent)

Plan your assessment

Choose support that fits your deadline

Tell us when you need Google's Letter of Validation and how much help you want. We'll suggest a plan, explain why it fits, and show the price of every option.

CASA plan finder

Find your CASA AL1 plan

Your recommendation and all prices appear at the end.

About 30 seconds

Step 1 of 4

When do you need to submit your CASA assessment?

Choose the closest window. If you know the exact date, you can add it below.

Before validation

Technical scan & tooling
requirements

CASA AL1 accepts specific authenticated scan artifacts and scope boundaries. Meet these criteria before your Letter of Validation can be processed.

Accepted scanning engines

  • OWASP ZAP: authenticated dynamic application security testing (DAST) scans, exporting full XML/JSON results mapped against ADA CWE requirements.
  • Burp Suite Professional / Enterprise: authenticated XML/HTML issue reports with HTTP request/response proofs.

Scan scope boundary

  • Must be run against the active production or production-identical staging environment with OAuth integration.
  • Must execute with an active authenticated session (session cookie, bearer token, or OAuth context) covering all endpoints accessible by the OAuth client.

Acceptance criteria

  • Zero unmitigated findings associated with high-likelihood MITRE Common Weakness Enumerations (CWEs) as outlined in the ADA CASA framework.
  • Valid justifications or false-positive verifications for medium-severity findings.

After checkout

What happens after checkout

Payment isn't a black hole — here's the exact fulfillment pipeline from purchase to signed LoV.

  1. Step 1Day 1

    Intake & scope confirmation

    Submit your Google Cloud project number, target app URL, and test account credentials via the Secusy customer portal.

  2. Step 2Days 1–2

    Self-Assessment Questionnaire

    Start filling out the SAQ, providing required responses and evidence.

  3. Step 3Days 1–2

    Automated scanning & evidence gathering

    Run our integrated scanner, or provide your ZAP or Burp authenticated scan results mapped against the ADA CASA requirements.

  4. Step 4Days 2–4

    AppSec verification & remediation

    A certified security engineer verifies the scan outputs and SAQ responses, helps dispute false positives, and provides remediation guidance to resolve genuine blockers.

  5. Step 5Day 5

    Official LoV submission

    LoV is submitted to Google's security team for approval. Download your signed, timestamped Letter of Validation from the portal once issued.

Who needs CASA AL1?

Web apps, browser extensions, and SaaS tools requesting Google OAuth sensitive scopes —e.g. Google Drive metadata, Google Calendar, or Contacts — fall under this requirement.

Questions

Frequently asked questions