
CASA Tier 2
Sledge completed a Cloud Application Security Assessment (CASA) at Tier 2, independently assessed by TAC Security, an App Defense Alliance authorized lab. The review covers the Sledge web app and APIs against the OWASP Application Security Verification Standard, the open benchmark for application security.
Independently assessed, not self-declared
Google requires a CASA assessment before an application can access sensitive Google user data. CASA is run by the App Defense Alliance and is built on the OWASP Application Security Verification Standard (ASVS). Tier 2 is a lab-verified review: Sledge was assessed by TAC Security, an App Defense Alliance authorized lab, rather than self-attested. Passing it means an independent third party checked how Sledge handles connected data against that standard. It is not a Google endorsement of Sledge.
Badges are shown to identify the assessment, the program and the lab. They are not a claim that any of them endorses Sledge.
A risk-based, standardized assessment
CASA was created by the App Defense Alliance to harden the application layer of cloud-to-cloud integrations. It gives every app a consistent, published way to show it handles sensitive user data safely, built on the OWASP Application Security Verification Standard, with a risk-based, multi-tier assessment approach.
One open standard
Built on the OWASP ASVS, so there are no proprietary requirements to decode.
Same bar for everyone
Every application is measured against the same requirements and the same process.
Published in the open
The requirements, the assessment methods, and the authorized labs are all public.
Scaled to risk
How deep the review goes depends on the risk tier, so testing is not one size fits all.
Assurance tiers
Self scan
An automated self-assessment against the ASVS, submitted by the developer.
Verified assessment
Automated testing plus independent validation by an App Defense Alliance authorized lab. This is the tier Sledge holds.
Manual assessment
A full manual penetration test, for the highest-risk applications.
Sledge asks for the narrowest access that does the job
When you connect Google Workspace to Sledge, Sledge requests only the permissions the feature you turned on actually needs. You see and approve exactly what Sledge can reach when you connect, and you can take that access away at any time from your Google account.
Only the permissions in use
Sledge asks for specific permissions tied to a feature you turn on, such as reading job emails or filing documents. Never blanket access to your mailbox or drive.
You approve it first
Google's consent screen shows every permission before you approve it. Nothing is granted quietly, and you can review or remove access whenever you want.
Handled to the CASA standard
Connected Google data is encrypted in transit and at rest, and how Sledge handles it was checked against the OWASP ASVS in the Tier 2 assessment.
Never sold, never used for ads
Sledge does not sell your Google data, does not hand it over for advertising, and does not use it to train third-party AI models. It is used only for the features you turned on.
What it covers
The Tier 2 assessment checks the Sledge application against the OWASP ASVS across these areas:
Run your back office on software you can vouch for
Independently assessed. No contracts. No setup fees.