Skip to main content
Home/Services/Google CASA & MASA Testing
Security Testing

Google CASA & MASA Testing

App security assessment for Google Cloud and Android marketplace

Google CASA Google MASA OWASP ASVS OWASP MASVS
engagement log Google CASA & MASA Testing testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingInsecure Local Data Storagecritical
day 03findingMissing Certificate Pinninghigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
1-2 weekstypical duration $7,500fixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

Google's Cloud Application Security Assessment (CASA) and Mobile Application Security Assessment (MASA) are required for apps that access Google user data or want to display security badges on the Play Store. Our testing satisfies CASA Tier 2/3 and MASA requirements with authorized lab-quality assessments.

What we test

For CASA, we assess web applications, APIs, and cloud services that integrate with Google APIs and handle Google user data. For MASA, we test Android applications against the OWASP MASVS standard including data storage, cryptography, authentication, network security, platform interaction, and code quality.

Method

How we run it

Our CASA assessments follow the App Defense Alliance (ADA) methodology, testing against OWASP ASVS Level 1/2 requirements. MASA assessments follow OWASP MASVS and MSTG procedures. We provide detailed findings reports compatible with Google's submission requirements and work directly with the ADA process.

01

Application scope and data flow analysis

02

OWASP ASVS/MASVS control testing

03

Authentication and session management testing

04

Data storage and privacy assessment

05

Cryptographic implementation review

06

API and network security testing

07

Platform-specific security testing (Android/Cloud)

08

Google ADA submission documentation

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • CASA/MASA compliant security assessment report
  • OWASP ASVS or MASVS compliance mapping
  • Vulnerability findings with evidence
  • Google submission-ready documentation
  • API security assessment results
  • Data handling and privacy evaluation
  • Remediation guidance for identified issues
  • Retest validation report for resubmission
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Insecure Local Data Storage Missing Certificate Pinning Hardcoded API Keys or Secrets Insufficient OAuth Scope Validation Improper WebView Configuration Missing Root/Jailbreak Detection Insecure Inter-Process Communication Excessive Permission Requests
Fit

Who this is for

Apps Accessing Google User Data
Android Play Store Developers
Google Workspace Marketplace Apps
Google Cloud Marketplace Listings
OAuth-Integrated Applications
Companies Seeking Play Store Security Badge
Standards this supports

Findings are mapped to Google CASA, Google MASA, OWASP ASVS, OWASP MASVS, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!