Governing standard
App Defense Alliance CASA framework, Tier 3 / AL2
ADA Tier 3 compliant
10–14 day turnaround
Manual penetration testing for apps requesting restricted Google OAuth scopes (Gmail API, full Drive access, Google Classroom admin). Report and signed Letter of Validation delivered in 10–14 business days, submitted in the format Google Trust & Safety accepts.
Google flags an app for CASA Tier 3 when it requests a restricted scope — full Gmail access (
https://mail.google.com/) or unrestricted Drive access are the most common triggers. Tier 3 cannot be satisfied with an automated scanner report; Google requires a manual penetration test performed by an authorized lab, plus a signed Letter of Validation.
The definition
App Defense Alliance CASA framework, Tier 3 / AL2
OWASP ASVS v4.0.3, Level 2 controls
Full pentest report + signed Letter of Validation
10–14 business days from kickoff to draft report
Google CASA AL2 (Tier 3) applies to apps requesting restricted OAuth scopes.Two things distinguish it from AL1 (Tier 2):
AL1 allows a developer-run automated scan (Burp Suite, ZAP) with a self-attestation questionnaire. AL2 requires an independent, authorized third-party lab to run the test — you cannot self-certify. On this engagement, testing is performed by ValueMentor; the Letter of Validation is issued by TrustCB, an ADA-authorized certification body, based on ValueMentor's findings.
The engagement is scoped to OWASP ASVS Level 2 control families, applied specifically to the OAuth client and the APIs it touches: authentication and session handling, access control between tenants/roles, and injection/input handling on every endpoint the OAuth grant can reach.
Source for scope requirements: App Defense Alliance / Google's own CASA documentation.
$5,400 USD flat fee, per application / OAuth Client ID.
$5,400one-time, per application
| In scope | Deliverables | Out of scope |
|---|---|---|
|
|
|
| Feature | AL1 (Tier 2) | AL2 (Tier 3) |
|---|---|---|
| Trigger scopes | Sensitive (Drive metadata, Calendar, Contacts) | Restricted (full Gmail, full Drive) |
| Who tests | Developer-run automated scan + self-attestation | Independent authorized lab, manual test |
| Human testing | Lab reviews scan output | Lab performs live manual testing |
| Price | From $499 | $5,400 flat |
| Retests | Per plan tier | Included, 60-day window |
| Turnaround | 2–5 business days | 10–14 business days |
| Deliverable | Signed LoV | Full pentest report + signed LoV |
Need AL1 instead?
View the CASA AL1 assessmentManual test plan
What we actually test, mapped to OWASP ASVS control families a technical buyer can verify against the standard itself.
Environment: Testing runs against a staging environment or production-replica with live OAuth integration, provided by the customer at kickoff.
After checkout
10–14 business days from kickoff to signed Letter of Validation.
Submit your Google Cloud Project ID, OAuth Client ID(s), architecture overview, and staging credentials through the customer portal. Scope confirmed within 24 hours.
Lead engineer executes the ASVS L2 test plan against the scoped application.
Customer receives the findings report with PoC steps and remediation guidance; one debrief call is held with the engineering team.
Customer patches; Secusy retests flagged findings at no extra charge.
ValueMentor confirms clean retest; TrustCB issues the signed Letter of Validation, formatted for Google Trust & Safety submission.
Questions
Flat fee, fixed scope, 10–14 business day turnaround. Submit your OAuth Client ID and staging access to start the kickoff.