Trust CenterCASA Tier 2
CASA Tier II assessment badge
Certified

CASA Tier 2

Cloud Application Security Assessment

Sledge completed a Cloud Application Security Assessment (CASA) at Tier 2, independently assessed by TAC Security, an App Defense Alliance authorized lab. The review covers the Sledge web app and APIs against the OWASP Application Security Verification Standard, the open benchmark for application security.

Back to Trust Center
Status
Certified
Assessed by
TAC Security
Scope
Sledge web app and APIs
Issued
Date to be published
Level
Tier 2
Last reviewed
August 2026
The program

Independently assessed, not self-declared

Google requires a CASA assessment before an application can access sensitive Google user data. CASA is run by the App Defense Alliance and is built on the OWASP Application Security Verification Standard (ASVS). Tier 2 is a lab-verified review: Sledge was assessed by TAC Security, an App Defense Alliance authorized lab, rather than self-attested. Passing it means an independent third party checked how Sledge handles connected data against that standard. It is not a Google endorsement of Sledge.

Badges are shown to identify the assessment, the program and the lab. They are not a claim that any of them endorses Sledge.

How CASA Tier 2 works

A risk-based, standardized assessment

CASA was created by the App Defense Alliance to harden the application layer of cloud-to-cloud integrations. It gives every app a consistent, published way to show it handles sensitive user data safely, built on the OWASP Application Security Verification Standard, with a risk-based, multi-tier assessment approach.

One open standard

Built on the OWASP ASVS, so there are no proprietary requirements to decode.

Same bar for everyone

Every application is measured against the same requirements and the same process.

Published in the open

The requirements, the assessment methods, and the authorized labs are all public.

Scaled to risk

How deep the review goes depends on the risk tier, so testing is not one size fits all.

Assurance tiers

Tier 1

Self scan

An automated self-assessment against the ASVS, submitted by the developer.

Tier 2Sledge

Verified assessment

Automated testing plus independent validation by an App Defense Alliance authorized lab. This is the tier Sledge holds.

Tier 3

Manual assessment

A full manual penetration test, for the highest-risk applications.

The access Sledge asks for

Sledge asks for the narrowest access that does the job

When you connect Google Workspace to Sledge, Sledge requests only the permissions the feature you turned on actually needs. You see and approve exactly what Sledge can reach when you connect, and you can take that access away at any time from your Google account.

Only the permissions in use

Sledge asks for specific permissions tied to a feature you turn on, such as reading job emails or filing documents. Never blanket access to your mailbox or drive.

You approve it first

Google's consent screen shows every permission before you approve it. Nothing is granted quietly, and you can review or remove access whenever you want.

Handled to the CASA standard

Connected Google data is encrypted in transit and at rest, and how Sledge handles it was checked against the OWASP ASVS in the Tier 2 assessment.

Never sold, never used for ads

Sledge does not sell your Google data, does not hand it over for advertising, and does not use it to train third-party AI models. It is used only for the features you turned on.

What it covers

The Tier 2 assessment checks the Sledge application against the OWASP ASVS across these areas:

Sign-in and session handling
Access control and authorization
Input validation and injection defense
Cryptography and secrets handling
API and web service security
Logging and error handling

Run your back office on software you can vouch for

Independently assessed. No contracts. No setup fees.

CASA Tier 2 — Certified | Sledge Security