Google CASA & MASA Testing
App security assessment for Google Cloud and Android marketplace
What this engagement covers
The service
Google's Cloud Application Security Assessment (CASA) and Mobile Application Security Assessment (MASA) are required for apps that access Google user data or want to display security badges on the Play Store. Our testing satisfies CASA Tier 2/3 and MASA requirements with authorized lab-quality assessments.
What we test
For CASA, we assess web applications, APIs, and cloud services that integrate with Google APIs and handle Google user data. For MASA, we test Android applications against the OWASP MASVS standard including data storage, cryptography, authentication, network security, platform interaction, and code quality.
How we run it
Our CASA assessments follow the App Defense Alliance (ADA) methodology, testing against OWASP ASVS Level 1/2 requirements. MASA assessments follow OWASP MASVS and MSTG procedures. We provide detailed findings reports compatible with Google's submission requirements and work directly with the ADA process.
Application scope and data flow analysis
OWASP ASVS/MASVS control testing
Authentication and session management testing
Data storage and privacy assessment
Cryptographic implementation review
API and network security testing
Platform-specific security testing (Android/Cloud)
Google ADA submission documentation
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- CASA/MASA compliant security assessment report
- OWASP ASVS or MASVS compliance mapping
- Vulnerability findings with evidence
- Google submission-ready documentation
- API security assessment results
- Data handling and privacy evaluation
- Remediation guidance for identified issues
- Retest validation report for resubmission
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Findings are mapped to Google CASA, Google MASA, OWASP ASVS, OWASP MASVS, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.