ADA Tier 3 compliant

10–14 day turnaround

Google CASA Tier 3 (AL2) Penetration Test & Letter of Validation

Manual penetration testing for apps requesting restricted Google OAuth scopes (Gmail API, full Drive access, Google Classroom admin). Report and signed Letter of Validation delivered in 10–14 business days, submitted in the format Google Trust & Safety accepts.

Backed byan authorized testing lab & certification body.
ComplianceApp Defense Alliance Tier 3 compliant
TestingValueMentor
CertificationTrustCB
Governing standardApp Defense Alliance CASA framework, Tier 3 / AL2
Testing standardOWASP ASVS v4.0.3, Level 2 controls
DeliverableFull pentest report + signed Letter of Validation
Turnaround10–14 business days from kickoff to draft report
LoV validity12 months (Google requires annual re-assessment)

Google flags an app for CASA Tier 3 when it requests a restricted scope — full Gmail access (https://mail.google.com/) or unrestricted Drive access are the most common triggers. Tier 3 cannot be satisfied with an automated scanner report; Google requires a manual penetration test performed by an authorized lab, plus a signed Letter of Validation.

The definition

What is a CASA AL2 assessment?

Google CASA Tier 3 (Assurance Level 2) is a manual penetration test required for apps requesting restricted OAuth scopes, such as full Gmail access or unrestricted Drive access. Unlike CASA AL1, it cannot be satisfied with an automated scanner report — it requires an independent, App Defense Alliance-authorized lab to perform hands-on testing and issue a signed Letter of Validation that Google Trust & Safety accepts.
  • Governing standard

    App Defense Alliance CASA framework, Tier 3 / AL2

  • Testing standard

    OWASP ASVS v4.0.3, Level 2 controls

  • Deliverable

    Full pentest report + signed Letter of Validation

  • Turnaround

    10–14 business days from kickoff to draft report

What CASA AL2 actually requires

Google CASA AL2 (Tier 3) applies to apps requesting restricted OAuth scopes.Two things distinguish it from AL1 (Tier 2):

  • Who tests it

    AL1 allows a developer-run automated scan (Burp Suite, ZAP) with a self-attestation questionnaire. AL2 requires an independent, authorized third-party lab to run the test — you cannot self-certify. On this engagement, testing is performed by ValueMentor; the Letter of Validation is issued by TrustCB, an ADA-authorized certification body, based on ValueMentor's findings.

  • What's tested

    The engagement is scoped to OWASP ASVS Level 2 control families, applied specifically to the OAuth client and the APIs it touches: authentication and session handling, access control between tenants/roles, and injection/input handling on every endpoint the OAuth grant can reach.

Source for scope requirements: App Defense Alliance / Google's own CASA documentation.

CASA AL2 assessment package

$5,400 USD flat fee, per application / OAuth Client ID.

In scopeDeliverablesOut of scope
  • 1 web application / 1 OAuth Client ID and the APIs it authenticates against
  • Manual penetration test mapped to ASVS L2 control families: authentication, session management, access control, input handling
  • IDOR/BOLA testing across tenant and role boundaries
  • TLS/cipher configuration review for endpoints in scope
  • Retesting of previously flagged findings, included, within 60 days of the draft report
  • One assigned lead engineer as point of contact for the engagement
  • Signed Letter of Validation, issued by TrustCB, in the format Google Trust & Safety requires
  • Full technical report from ValueMentor: findings, severity (CVSS-scored), proof-of-concept steps, remediation guidance
  • One remediation debrief call with your engineering team
  • Additional OAuth Client IDs or applications beyond the one scoped
  • Retests requested after the 60-day window
  • Infrastructure/network penetration testing beyond what the OAuth client touches
  • Need expedited turnaround? Let's discuss.

CASA AL1 vs AL2

FeatureAL1 (Tier 2)AL2 (Tier 3)
Trigger scopesSensitive (Drive metadata, Calendar, Contacts)Restricted (full Gmail, full Drive)
Who testsDeveloper-run automated scan + self-attestationIndependent authorized lab, manual test
Human testingLab reviews scan outputLab performs live manual testing
PriceFrom $499$5,400 flat
RetestsPer plan tierIncluded, 60-day window
Turnaround2–5 business days10–14 business days
DeliverableSigned LoVFull pentest report + signed LoV

Manual test plan

Testing methodology

What we actually test, mapped to OWASP ASVS control families a technical buyer can verify against the standard itself.

Authentication & session (ASVS V2/V3)

  • MFA enforcement checks, session timeout and fixation testing, OAuth state parameter validation, token entropy and leakage testing, logout/token revocation verification.

Access control (ASVS V4)

  • Horizontal and vertical privilege escalation attempts across at least two provisioned test personas — tenant isolation testing for multi-tenant SaaS architectures, IDOR testing on every object reference exposed via the OAuth-scoped APIs.

Input handling (ASVS V5)

  • SQLi, NoSQLi, stored/reflected XSS, SSRF, and command injection testing on customer-facing REST/GraphQL endpoints reachable by the OAuth client.

Environment: Testing runs against a staging environment or production-replica with live OAuth integration, provided by the customer at kickoff.

After checkout

Engagement timeline

10–14 business days from kickoff to signed Letter of Validation.

  1. Step 1Day 1

    Kickoff & scope lock

    Submit your Google Cloud Project ID, OAuth Client ID(s), architecture overview, and staging credentials through the customer portal. Scope confirmed within 24 hours.

  2. Step 2Days 2–8

    Manual testing

    Lead engineer executes the ASVS L2 test plan against the scoped application.

  3. Step 3Days 9–10

    Draft report & debrief

    Customer receives the findings report with PoC steps and remediation guidance; one debrief call is held with the engineering team.

  4. Step 4Up to 60 days

    Remediation window

    Customer patches; Secusy retests flagged findings at no extra charge.

  5. Step 52 days post-retest

    Final delivery

    ValueMentor confirms clean retest; TrustCB issues the signed Letter of Validation, formatted for Google Trust & Safety submission.

Questions

Frequently asked questions

Start your CASA AL2 assessment

Flat fee, fixed scope, 10–14 business day turnaround. Submit your OAuth Client ID and staging access to start the kickoff.