App security assessment for Google Cloud and Android marketplace
A comprehensive assessment tailored to your environment.
Google's Cloud Application Security Assessment (CASA) and Mobile Application Security Assessment (MASA) are required for apps that access Google user data or want to display security badges on the Play Store. Our testing satisfies CASA Tier 2/3 and MASA requirements with authorized lab-quality assessments.
For CASA, we assess web applications, APIs, and cloud services that integrate with Google APIs and handle Google user data. For MASA, we test Android applications against the OWASP MASVS standard including data storage, cryptography, authentication, network security, platform interaction, and code quality.
Our CASA assessments follow the App Defense Alliance (ADA) methodology, testing against OWASP ASVS Level 1/2 requirements. MASA assessments follow OWASP MASVS and MSTG procedures. We provide detailed findings reports compatible with Google's submission requirements and work directly with the ADA process.
Everything included in your engagement report.
CASA/MASA compliant security assessment report
OWASP ASVS or MASVS compliance mapping
Vulnerability findings with evidence
Google submission-ready documentation
API security assessment results
Data handling and privacy evaluation
Remediation guidance for identified issues
Retest validation report for resubmission
A structured approach to identifying and validating vulnerabilities.
Application scope and data flow analysis
OWASP ASVS/MASVS control testing
Authentication and session management testing
Data storage and privacy assessment
Cryptographic implementation review
API and network security testing
Platform-specific security testing (Android/Cloud)
Google ADA submission documentation
Typical security issues discovered during this type of engagement.
Complementary security engagements for comprehensive coverage.
OSCP, OSCE, CEH, GPEN certified professionals
Reports designed for compliance audits
Validate fixes at no additional cost
Direct access to testing team during remediation