Caddi Completes CASA AL1 Security Assessment for Google Workspace
Caddi completed the Cloud Application Security Assessment (CASA) at Assurance Level 1, validated by TAC Security. CASA is the assessment Google requires before an app can use restricted scopes in Gmail, Drive, Docs, and Sheets.
Caddi has completed CASA Assurance Level 1 (formerly CASA Tier 2). The assessment was validated by TAC Security, one of the labs the App Defense Alliance authorizes to run CASA. It sits alongside our SOC 2 Type II report as the second independent review of how Caddi handles your firm's data.
Why Caddi needed it
Caddi agents do the work that runs through a firm's Google Workspace: reading an intake email, filing the attachment to the right Drive folder, filling a Doc from a template, updating the tracking Sheet. Google classifies the access that work needs as restricted scopes, its most sensitive tier of API access. Any app that requests restricted scopes and handles that data on its own servers has to pass a CASA assessment, and has to repeat it every twelve months.
What CASA is
CASA (Cloud Application Security Assessment) is a framework run by the App Defense Alliance and built on the OWASP Application Security Verification Standard (ASVS). Google decides which level an app needs based on the scopes it requests. The levels share one set of requirements and differ in who does the testing:
| Level | Former name | Who tests |
|---|---|---|
| AL1 | Tier 2 | The developer tests against the CASA requirements; an authorized lab reviews the evidence and issues a Letter of Validation. |
| AL2 | Tier 3 | The authorized lab tests the running application and its infrastructure itself. |
What the assessment covers
The CASA requirements look at how an application protects the user data it is trusted with, including:
- Authentication and session handling. How users sign in and how sessions are issued, expired, and revoked.
- Access control. That each user and each request reaches only the data it is entitled to.
- Data protection and cryptography. How OAuth tokens and Google data are stored and encrypted.
- Input handling. Defences against injection and malicious input.
- Logging and data deletion. What is recorded, and that data is removed when access ends.
How this shows up when you connect Google
- OAuth, never passwords. You connect Gmail, Drive, Docs, or Sheets through Google's own consent screen. Caddi never sees your Google password.
- Scoped to the work. Each agent runs under the access the person who connected it already had, one scope per system, with no standing admin.
- Every run on the record. Each action an agent takes in your Workspace is logged and replayable, with the permission it used.
- Disconnect means disconnect. Pull the connection in Caddi or revoke Caddi in your Google account, and the agents stop.
CASA and SOC 2 Type II
The two answer different questions, which is why a security review will ask for both. SOC 2 Type II is an audit of Caddi's controls as a company, observed over a period of time. CASA looks at the application itself and how it treats the Google data it is given. A firm connecting its inbox and document store to an agent should expect a vendor to have both.
What we claim, and what we do not
CASA is an assessment, not a certification, and it is not an endorsement of Caddi by Google or the App Defense Alliance. What we claim is exactly what the Letter of Validation says: Caddi completed CASA at Assurance Level 1, validated by TAC Security. Your own vendor review still matters, and we would rather hand you the documents than ask you to take a badge on trust.
Request the CASA Letter of Validation and our SOC 2 Type II report in the Caddi Trust Center, or see how Caddi connects to your tools on the technology page.
Frequently asked questions
What is CASA?
CASA (Cloud Application Security Assessment) is the App Defense Alliance framework Google uses to check how an app handles Google user data. It is built on the OWASP Application Security Verification Standard (ASVS), and Google requires it for apps that request restricted scopes, such as Gmail and Drive access.
What is the difference between AL1 and Tier 2?
They are the same level under two names. The App Defense Alliance renamed CASA Tier 2 to Assurance Level 1 (AL1). At AL1 the developer tests the app against the CASA requirements and an authorized lab validates the evidence before issuing a Letter of Validation.
Who assessed Caddi?
TAC Security, an App Defense Alliance authorized CASA lab, validated Caddi's assessment.
Is CASA a certification?
No. CASA is an assessment, and the App Defense Alliance does not describe it as a certification. It is also not a Google endorsement of Caddi. It shows that an authorized lab validated how Caddi handles Google user data against the CASA requirements.
How does CASA relate to SOC 2 Type II?
They answer different questions. SOC 2 Type II is an independent audit of Caddi's security controls as a company, over a period of time. CASA looks at the application itself and how it stores, protects, and deletes the Google data it is given access to. Caddi has both.
How often is CASA renewed?
Google requires the assessment to be repeated every twelve months for apps that keep restricted scopes.
Can I get a copy of the Letter of Validation?
Yes. Request it, along with our SOC 2 Type II report, through the Caddi Trust Center at trust.trycaddi.com.
Caddi
