I will prepare your saas for google oauth casa assessment


About this gig
Google told you your OAuth app needs a CASA security assessment, and you're not sure what that means before spending money.
CASA is run by the App Defense Alliance, not by me. An ADA-authorized lab tests your app and issues the result Google accepts I can't certify your app, guarantee approval, or issue official CASA documentation.
What I do is the work before that: translating CASA's requirements (OAuth flow, session handling, token storage, TLS, input validation) into steps your team can act on, and flagging the gaps likely to cause delays. Where useful, I can work directly with your developer to run applicable scans OWASP ZAP (DAST) and, where appropriate, Fluid Attacks (SAST) review the findings, and fix and re-test issues. i also help prepare the evidence a lab will ask for, so you walk into the real assessment prepared.
Background: I have handled Google OAuth verification for restricted-scope apps, including gmail.modify, through scope audits and Trust & Safety feedback rounds.
Message me your scopes before ordering so i can tell you honestly if this is the right fit.
Get to know Partha Das
Software developer, Open Source Contributor at stdlib
- FromBangladesh
- Member sinceDec 2024
- Avg. response time4 hours
- Last delivery5 days
Languages
English
My Portfolio
FAQ
Are you an ADA-authorized CASA assessor? Can you certify my app?
No. Only labs on ADA's authorized list (NCC Group, Bishop Fox, TAC Security, and a few others) can run the official assessment and issue a result Google accepts. I'm not one of them, and I can't certify your app or issue official CASA documentation. My job is getting your app ready before you engage
Will this guarantee my app passes the assessment?
No one can honestly promise that — the result depends on the authorized lab's testing and Google's review, not on me. What I can do is fix the issues most likely to cause a fail or a slow re-review, so you go in with a much stronger app.
Do I still need to pay for the official assessment after working with you?
Yes. This is prep work, not a substitute. Once your app is ready, you'll still engage an ADA-authorized lab directly for the actual AL1 or AL2 assessment — I can point you to a few once you're at that stage.
Which package do I need if I haven't done Google OAuth verification yet?
Go with Premium. Basic and Standard assume verification is already handled and focus purely on CASA readiness; Premium bundles full OAuth verification (scopes, consent screen, demo video, submission, Google follow-up) with the CASA prep.
Do you have hands-on experience with restricted scopes like Gmail?
Yes — I've handled Google OAuth verification for apps on restricted scopes, including gmail.modify, working through scope audits and Trust & Safety feedback rounds directly. That's the same category of access most CASA-triggering apps use.
What do you need from me or my developer to get started?
A rundown of the scopes you're requesting, read access to the relevant code (or working sessions with your developer), and your OAuth/Cloud Console config. No production data or user access required.

